PT-2025-23640 · Unknown · Jupyter Core

·

CVE-2025-30167

·

Published

2025-02-13

·

Updated

2026-07-07

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jupyter Core versions prior to 5.8.0
Description The issue affects Jupyter Core on Windows, where the shared %PROGRAMDATA% directory is searched for configuration files, potentially allowing users to create files that impact other users. This is specifically a concern for shared Windows systems with multiple users and an unprotected %PROGRAMDATA% directory.
Recommendations For versions prior to 5.8.0, upgrade to Jupyter Core version 5.8.0 or later. As an administrator, modify the permissions on the %PROGRAMDATA% directory to prevent unauthorized write access. As an administrator, create the %PROGRAMDATA%jupyter directory with restrictive permissions. As a user or administrator, set the %PROGRAMDATA% environment variable to a directory with restrictive permissions, such as one controlled by administrators or the current user.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06495
CVE-2025-30167
GHSA-33P9-3P43-82VQ
OPENSUSE-SU-2025:15272-1
PYSEC-2026-1477
ZDI-25-339

Affected Products

Jupyter Core