PT-2026-95109 · Project Jupyter · Jupyter Server

·

CVE-2026-86049

·

Published

2026-09-17

·

Updated

2026-10-01

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jupyter Server versions prior to 2.21.0
Description In the 5xx request logging path within jupyter server/log.py, the Referer header is copied into a JSON header block without applying the token scrubbing typically used for the request URI. When a request returns an HTTP 500 error and the Referer header contains a URL with a token, that token is written to the server logs in plaintext. An attacker with access to these logs can recover the token to gain the permissions of the affected user.
Recommendations Update to version 2.21.0 or later. Limit access to server logs to authorized personnel only. Avoid workflows that place tokens directly in the URL.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86049
GHSA-C3MW-737P-C7G2
PYSEC-2026-4054

Affected Products

Jupyter Server