Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.
References
Configurations
History
22 Jul 2026, 12:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
30 Jun 2026, 03:20
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp - Mitigation, Patch, Vendor Advisory |
26 Jun 2026, 18:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bd - Patch | |
| References | () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmp - Patch, Vendor Advisory, Mitigation | |
| CPE | cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:* | |
| First Time |
Jupyter jupyter Server
Jupyter |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
22 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 21:16
Updated : 2026-07-22 12:18
NVD link : CVE-2026-44727
Mitre link : CVE-2026-44727
CVE.ORG link : CVE-2026-44727
JSON object : View
Products Affected
jupyter
- jupyter_server
