THREAT OPS › Threat News › [NVD] CVE-2026-35397 (HIGH 8.8) — Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the r
[NVD] CVE-2026-35397 (HIGH 8.8) — Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the r
CVE-2026-35397 CVSS: 8.8 HIGH Published: 2026-05-05T20:16:38.223
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named "test", th
Indicators of compromise
- CVE-2026-35397cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-35397