CVE-2026-23528: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-23528 is a cross-site scripting (XSS) vulnerability in Dask distributed that can lead to remote code execution when used alongside Jupyter Lab and jupyter-server-proxy. Disclosed on January 16, 2026, it affects all versions of the distributed package prior to 2026.1.0 (pip) and prior to 2026.1.0 (conda). An attacker can craft a phishing URL that, when clicked by a victim running the affected stack on default ports, causes arbitrary Python code to execute via the Jupyter kernel. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, Dask Security Advisory).

Technical details

The root cause is improper neutralization of user-controlled input in the Dask dashboard's HTTP proxy handler (distributed/http/proxy.py), classified as CWE-79 (Cross-site Scripting), CWE-80 (Basic XSS), and CWE-250 (Execution with Unnecessary Privileges). Specifically, the http_get handler in the proxy module reflected the host and port path parameters directly into an error message without HTML escaping, allowing injection of arbitrary HTML/script content. When Jupyter Lab's jupyter-server-proxy forwards requests to the Dask dashboard, the XSS payload is rendered in the browser context of the Jupyter origin, which then triggers code execution via the Jupyter Python kernel. The fix applied html.escape() to the worker string before including it in the error response (Dask Commit, Dask Security Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute arbitrary Python code in the context of the victim's Jupyter kernel, with whatever privileges the Jupyter process holds. This can result in unauthorized access to notebooks, data, credentials, and files accessible to the Jupyter user, as well as integrity compromise through modification of notebooks or local files. Availability is not directly impacted, but the code execution primitive could be leveraged for further lateral movement within the victim's environment (Github Advisory, Dask Security Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported as of the time of this report. The EPSS score is approximately 0.047% (very low probability of exploitation in the next 30 days), and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires social engineering — the victim must click a specially crafted phishing URL while running Jupyter Lab with jupyter-server-proxy and a Dask distributed cluster, both on their default ports (Github Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify or assume a target is running Jupyter Lab on the default port (typically 8888) with jupyter-server-proxy installed, and a Dask distributed cluster on its default dashboard port (typically 8787) on localhost.
  2. Craft malicious URL: Construct a URL targeting the Dask dashboard proxy endpoint via Jupyter Lab's proxy, embedding XSS payload characters in the host path segment — e.g., http://localhost:8888/proxy/8787/<script>malicious_code</script>/status. The unescaped host value is reflected in the error response.
  3. Deliver phishing link: Send the crafted URL to the target user via email, chat, or a malicious web page, enticing them to click it.
  4. XSS triggers in Jupyter context: When the victim clicks the link, their browser opens the Dask dashboard error page via the Jupyter proxy. The injected script executes in the Jupyter Lab browser origin.
  5. Achieve code execution: The malicious JavaScript leverages Jupyter's kernel API (accessible from the same origin) to execute arbitrary Python code in the victim's active Jupyter kernel, enabling data exfiltration, file access, or further system compromise (Dask Security Advisory, Dask Commit).

Indicators of compromise

  • Network: Unexpected HTTP requests to the Jupyter Lab proxy endpoint targeting the Dask dashboard (e.g., GET /proxy/8787/<encoded_payload>/status) originating from external or unusual sources; outbound connections from the Jupyter process to unknown hosts following such requests.
  • Logs: Jupyter server access logs showing requests to /proxy/<port>/<host_with_special_chars>/ paths; Dask dashboard logs showing 400 error responses with unusual host values containing HTML special characters (<, >).
  • Process: Unexpected child processes or network connections spawned by the Jupyter Python kernel process (e.g., curl, wget, python -c, reverse shell processes) following a user clicking an external link.
  • File System: Newly created or modified files in the Jupyter working directory or user home directory that were not created by the user directly, potentially indicating kernel-executed file writes.

Mitigation and workarounds

The primary fix is to upgrade dask distributed to version 2026.1.0 or later (pip) or 2025.9.2 / 2026.1.1 or later (conda), which applies proper HTML escaping to reflected values in the proxy error handler. There are no complete workarounds, but risk can be reduced by: (1) uninstalling jupyter-server-proxy to prevent the XSS from escalating to code execution (though reflected XSS in the Dask dashboard itself remains); or (2) running Jupyter Lab and the Dask dashboard on non-default ports to reduce the effectiveness of generic phishing URLs. Users should treat any unsolicited links to their local Jupyter or Dask instances with suspicion (Dask Security Advisory, Github Advisory).

Community reactions

The advisory was published by Dask maintainer jacobtomlinson on January 16, 2026, and was picked up by standard vulnerability aggregators including Tenable (Nessus plugin 291276), Qualys, Red Hat, and INCIBE-CERT shortly after disclosure. No significant independent researcher commentary or broad social media discussion has been identified beyond routine CVE tracking and aggregation (Dask Security Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

dask.distributed

Affected

sid

dask.distributed: 2024.12.1+ds-3

Fixed

trixie

dask.distributed

Affected

Ubuntu

Unknown

bionic (esm-apps)

dask.distributed

Unknown

devel

dask.distributed

Unknown

focal (esm-apps)

dask.distributed

Unknown

jammy

dask.distributed

Unknown

jammy (esm-apps)

dask.distributed

Unknown

noble

dask.distributed

Unknown

noble (esm-apps)

dask.distributed

Unknown

resolute

dask.distributed

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management