VYPR
Medium severity6.8NVD Advisory· Published Jun 2, 2026

CVE-2026-5422

CVE-2026-5422

Description

Path traversal in jupyter-server 2.17.0 allows unauthorized file access due to improper path boundary checks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Path traversal in jupyter-server 2.17.0 allows unauthorized file access due to improper path boundary checks.

Vulnerability

A path traversal vulnerability exists in jupyter-server version 2.17.0. The _get_os_path() function in jupyter_server/services/contents/fileio.py incorrectly checks the root directory boundary using startswith(root) without appending a trailing path separator. This allows sibling directories with names starting with the same prefix as root_dir to bypass the check. Furthermore, the to_os_path() function in utils.py does not strip .. from path parts, enabling traversal sequences to bypass the vulnerable check [1].

Exploitation

An attacker needs to be able to interact with the jupyter-server instance. By crafting a malicious path that includes .. sequences and a filename that shares a prefix with the intended root directory, an attacker can manipulate the path to access files outside the intended directory structure [1].

Impact

Successful exploitation allows an attacker to gain unauthorized read or write access to files located in sibling directories relative to the jupyter-server's root directory. This could lead to the exposure of sensitive data, particularly in shared hosting environments where multiple users or applications share the same server [1].

Mitigation

Jupyter-server version 2.17.0 is affected. A fix is available in later versions of jupyter-server. Users are advised to upgrade to a patched version as soon as possible. Specific patch version and release date are not detailed in the available references [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.