4 known bugs in jupyter_core, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
| Severity | Affected | Fixed in | Title | Status | Source |
|---|
| high | any | 4.11.2 | Execution with Unnecessary Privileges in JupyterApp ### Impact
_What kind of vulnerability is it? Who is impacted?_
We’d like to disclose an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in the current working directory. This vulnerability allows one user to run code as another.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
Users should upgrade to `jupyter_core>=4.11.2`.
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
No
### References
_Are there any links users can visit to find out more?_
Similar advisory in [IPython](https://github.com/advisories/GHSA-pq7m-3gw7-gq5x)
| fixed | osv:GHSA-m678-f26j-3hrp |
| high | any | 5.8.1 | Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability ## Impact
On Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users.
Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected.
## Mitigations
- upgrade to `jupyter_core>=5.8.1` (5.8.0 is patched but breaks `jupyter-server`) , or
- as administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users, or
- as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions, or
- as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user)
## Credit
Reported via Trend Micro Zero Day Initiative as ZDI-CAN-25932 | fixed | osv:GHSA-33p9-3p43-82vq |
| medium | any | 5.8.1 | Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability ## Impact
On Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users.
Only shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected.
## Mitigations
- upgrade to `jupyter_core>=5.8.1` (5.8.0 is patched but breaks `jupyter-server`) , or
- as administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users, or
- as administrator, create the `%PROGRAMDATA%\jupyter` directory with appropriately restrictive permissions, or
- as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user)
## Credit
Reported via Trend Micro Zero Day Initiative as ZDI-CAN-25932 | fixed | osv:PYSEC-2026-1477 |
| medium | any | 1118c8ce01800cb689d51f655f5ccef19516e283 | PYSEC-2022-42974: advisory Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds. | fixed | osv:PYSEC-2022-42974 |
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/pypi/jupyter_core