云虫漏洞库

CVE-2026-44727 - Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed - 漏洞详情

漏洞编号:CVE-2026-44727

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-44727

CNNVD 编号:-

厂商/产品:jupyter / jupyter_server

影响范围:cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*

CWE:CWE-79

发布/更新时间:2026-06-22 / 2026-08-28

漏洞描述

Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.

相关链接

相关漏洞

« 返回首页