VYPR

nbviewer

by Jupyter

CVEs (1)

  • CVE-2026-86258Sep 6, 2026
    risk 0.00cvss epss

    nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the…