CVE-2025-30167
published 2025-06-03CVE-2025-30167: Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared…
PriorityP337high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.15%
5.0th percentile
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users; or as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions; or as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyter-core | — | — |
| jupyter | jupyter_core | < 5.8.0 | 5.8.0 |
| jupyter | jupyter_core | >= 0 < 5.8.1 | 5.8.1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.3HIGH
vendor_debian7.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-30167: jupyter-core - Jupyter Core is a package for the core common functionality of Jupyter projects....
vendor_debian·2025·CVSS 7.3
CVE-2025-30167 [HIGH] CVE-2025-30167: jupyter-core - Jupyter Core is a package for the core common functionality of Jupyter projects....
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users; or as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions; or as user or adminis
OSV
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
osv·2025-06-04
CVE-2025-30167 [HIGH] Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
## Impact
On Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users.
Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected.
## Mitigations
- upgrade to `jupyter_core>=5.8.1` (5.8.0 is patched but breaks `jupyter-server`) , or
- as administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users, or
- as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions, or
- as user or administrator, set the `%PRO
GHSA
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
ghsa·2025-06-04
CVE-2025-30167 [HIGH] CWE-427 Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
## Impact
On Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users.
Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected.
## Mitigations
- upgrade to `jupyter_core>=5.8.1` (5.8.0 is patched but breaks `jupyter-server`) , or
- as administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users, or
- as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions, or
- as user or administrator, set the `%PRO
OSV
CVE-2025-30167: Jupyter Core is a package for the core common functionality of Jupyter projects
osv·2025-06-03·CVSS 7.3
CVE-2025-30167 [HIGH] CVE-2025-30167: Jupyter Core is a package for the core common functionality of Jupyter projects
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users; or as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions; or as user or adminis
No detection rules found.
No writeups or analysis indexed.
2025-06-03
Published