jupyter-server@2.18.1

The backend—i.e. core services, APIs, and REST endpoints—to Jupyter web applications.

  • latest version

    2.19.0

  • first published

    7 years ago

  • latest version published

    13 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the jupyter-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal due to insufficient validation of file paths in _get_os_path() function within jupyter_server/services/contents/fileio.py. An attacker can gain unauthorized read and write access to files outside the intended directory by submitting crafted directory traversal sequences. This may result in exposure of sensitive data, especially in shared hosting environments.

    How to fix Directory Traversal?

    There is no fixed version for jupyter-server.

    [0,)