Medium severity5.4NVD Advisory· Published Jun 22, 2026· Updated Aug 28, 2026
CVE-2026-44727
CVE-2026-44727
Description
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel RCE. This vulnerability is fixed in 2.20.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jupyter-serverPyPI | < 2.20.0 | 2.20.0 |
Affected products
6cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*range: <2.20.0
- (no CPE)range: <2.20
- osv-coords4 versionspkg:apk/chainguard/tensorflow-cpu-jupyterpkg:apk/chainguard/tensorflow-gpu-jupyterpkg:apk/wolfi/tensorflow-cpu-jupyterpkg:rpm/opensuse/python-jupyter-server&distro=openSUSE%20Tumbleweed
< 2.21.0-r6+ 3 more
- (no CPE)range: < 2.21.0-r6
- (no CPE)range: < 2.21.0-r6
- (no CPE)range: < 2.21.0-r6
- (no CPE)range: < 2.20.0-1.1
Patches
Vulnerability mechanics
References
11- github.com/jupyter-server/jupyter_server/commit/6cbee8d65e71abac851c4492fea987ad080580bdnvdPatchWEB
- github.com/jupyter-server/jupyter_server/security/advisories/GHSA-fcw5-x6j4-ccmpnvdMitigationPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-fcw5-x6j4-ccmpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-44727ghsaADVISORY
- access.redhat.com/errata/RHSA-2026:43038nvdWEB
- access.redhat.com/errata/RHSA-2026:60520nvdWEB
- access.redhat.com/security/cve/CVE-2026-44727nvdWEB
- bugzilla.redhat.com/show_bug.cginvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-366.yamlghsaWEB
- pypi.org/project/jupyter-serverghsaWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44727.jsonnvdWEB
News mentions
0No linked articles in our index yet.