PT-2026-95109 · Project Jupyter · Jupyter Server
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jupyter Server versions prior to 2.21.0
Description
In the 5xx request logging path within
jupyter server/log.py, the Referer header is copied into a JSON header block without applying the token scrubbing typically used for the request URI. When a request returns an HTTP 500 error and the Referer header contains a URL with a token, that token is written to the server logs in plaintext. An attacker with access to these logs can recover the token to gain the permissions of the affected user.Recommendations
Update to version 2.21.0 or later.
Limit access to server logs to authorized personnel only.
Avoid workflows that place tokens directly in the URL.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyter Server