Jupyter Core vulnerabilities
2 known vulnerabilities affecting jupyter/jupyter_core.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-30167HIGHCVSS 7.3fixed in 5.8.02025-06-03
CVE-2025-30167 [HIGH] CWE-427 CVE-2025-30167: Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter
Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users. Only shared Wind
ghsanvd
CVE-2022-39286HIGHCVSS 8.8fixed in 4.11.22022-10-26
CVE-2022-39286 [HIGH] CWE-250 CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this is
nvd