THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-35397 (HIGH 8.8) — Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the r

[NVD] CVE-2026-35397 (HIGH 8.8) — Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the r

lownvdPublished 2026-05-05

CVE-2026-35397 CVSS: 8.8 HIGH Published: 2026-05-05T20:16:38.223

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named "test", th

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-35397