
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23528 is a cross-site scripting (XSS) vulnerability in Dask distributed that can lead to remote code execution when used alongside Jupyter Lab and jupyter-server-proxy. Disclosed on January 16, 2026, it affects all versions of the distributed package prior to 2026.1.0 (pip) and prior to 2026.1.0 (conda). An attacker can craft a phishing URL that, when clicked by a victim running the affected stack on default ports, causes arbitrary Python code to execute via the Jupyter kernel. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Dask Security Advisory).
The root cause is improper neutralization of user-controlled input in the Dask dashboard's HTTP proxy handler (distributed/http/proxy.py), classified as CWE-79 (Cross-site Scripting), CWE-80 (Basic XSS), and CWE-250 (Execution with Unnecessary Privileges). Specifically, the http_get handler in the proxy module reflected the host and port path parameters directly into an error message without HTML escaping, allowing injection of arbitrary HTML/script content. When Jupyter Lab's jupyter-server-proxy forwards requests to the Dask dashboard, the XSS payload is rendered in the browser context of the Jupyter origin, which then triggers code execution via the Jupyter Python kernel. The fix applied html.escape() to the worker string before including it in the error response (Dask Commit, Dask Security Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary Python code in the context of the victim's Jupyter kernel, with whatever privileges the Jupyter process holds. This can result in unauthorized access to notebooks, data, credentials, and files accessible to the Jupyter user, as well as integrity compromise through modification of notebooks or local files. Availability is not directly impacted, but the code execution primitive could be leveraged for further lateral movement within the victim's environment (Github Advisory, Dask Security Advisory).
No public exploit code or active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.047% (very low probability of exploitation in the next 30 days), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering — the victim must click a specially crafted phishing URL while running Jupyter Lab with jupyter-server-proxy and a Dask distributed cluster, both on their default ports (Github Advisory, Feedly).
jupyter-server-proxy installed, and a Dask distributed cluster on its default dashboard port (typically 8787) on localhost.host path segment — e.g., http://localhost:8888/proxy/8787/<script>malicious_code</script>/status. The unescaped host value is reflected in the error response.GET /proxy/8787/<encoded_payload>/status) originating from external or unusual sources; outbound connections from the Jupyter process to unknown hosts following such requests./proxy/<port>/<host_with_special_chars>/ paths; Dask dashboard logs showing 400 error responses with unusual host values containing HTML special characters (<, >).curl, wget, python -c, reverse shell processes) following a user clicking an external link.The primary fix is to upgrade dask distributed to version 2026.1.0 or later (pip) or 2025.9.2 / 2026.1.1 or later (conda), which applies proper HTML escaping to reflected values in the proxy error handler. There are no complete workarounds, but risk can be reduced by: (1) uninstalling jupyter-server-proxy to prevent the XSS from escalating to code execution (though reflected XSS in the Dask dashboard itself remains); or (2) running Jupyter Lab and the Dask dashboard on non-default ports to reduce the effectiveness of generic phishing URLs. Users should treat any unsolicited links to their local Jupyter or Dask instances with suspicion (Dask Security Advisory, Github Advisory).
The advisory was published by Dask maintainer jacobtomlinson on January 16, 2026, and was picked up by standard vulnerability aggregators including Tenable (Nessus plugin 291276), Qualys, Red Hat, and INCIBE-CERT shortly after disclosure. No significant independent researcher commentary or broad social media discussion has been identified beyond routine CVE tracking and aggregation (Dask Security Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
dask.distributed
sid
dask.distributed: 2024.12.1+ds-3
trixie
dask.distributed
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."