CVE-2020-26275
Python vulnerability analysis and mitigation

Overview

The Jupyter Server, which provides backend services, APIs, and REST endpoints for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila, was found to contain an open redirect vulnerability (CVE-2020-26275) before version 1.1.1. The vulnerability was discovered in December 2020 and could allow malicious actors to redirect users to untrusted websites (GitHub Advisory).

Technical details

The vulnerability exists in the server's URL handling mechanism where a maliciously crafted link to a Jupyter server could redirect the browser to a different website. The issue particularly affects Jupyter servers running without a base_url prefix. A link to a Jupyter server may appear safe but could ultimately redirect to a spoofed server on the public internet. This vulnerability is similar to one that was previously patched in upstream notebook v5.7.8 (GitHub Advisory).

Impact

The vulnerability could be exploited to conduct phishing attacks by redirecting users from legitimate Jupyter server instances to malicious websites. While all Jupyter servers running without a base_url prefix are technically affected, the exploitation requires the attacker to know the Jupyter server hosts. This could lead to users unknowingly accessing malicious servers while believing they are interacting with legitimate Jupyter instances (GitHub Advisory).

Exploitability

The vulnerability can be exploited by crafting malicious links that appear to point to legitimate Jupyter server instances. However, the exploitability is limited to scenarios where the attacker knows the target Jupyter server hosts. The attack requires creating specially crafted URLs that can redirect users to malicious websites (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in jupyter_server version 1.1.1. For users unable to upgrade, a workaround is available by running the server with a URL prefix using the command: 'jupyter server --ServerApp.base_url=/jupyter/' (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61539CRITICAL10
  • Python logoPython
  • xinference
NoYesAug 21, 2026
CVE-2026-49360HIGH7.8
  • Python logoPython
  • recce
NoYesAug 21, 2026
CVE-2026-68508HIGH7.8
  • Python logoPython
  • hydra-core
NoYesAug 21, 2026
CVE-2026-54457HIGH7.7
  • Python logoPython
  • tensorzero
NoYesAug 21, 2026
CVE-2026-43980MEDIUM6.3
  • Python logoPython
  • malla
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management