CVE-2026-5422
Description
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, the to_os_path() function in utils.py does not strip ".." from path parts, enabling traversal sequences to bypass the vulnerable check. This vulnerability can lead to unauthorized read/write access to files in sibling directories, potentially exposing sensitive data in shared hosting environments.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jupyter-serverPyPI | < 2.18.2 | 2.18.2 |
Affected products
3cpe:2.3:a:jupyter:jupyter_server:2.17.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:jupyter:jupyter_server:2.17.0:*:*:*:*:*:*:*
- (no CPE)range: <2.17.0
Patches
Vulnerability mechanics
References
6- huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0fnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gf7q-q4j7-hp7cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-5422ghsaADVISORY
- github.com/jupyter-server/jupyter_server/commit/0d829f2c35a481c3b24ecbe1e25a6f79954e88f2ghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2026-2532.yamlghsaWEB
- pypi.org/project/jupyter-serverghsaWEB
News mentions
0No linked articles in our index yet.