JVN#01719116
Jupyter Server vulnerable to open redirect
Overview
Jupyter Server provided by Jupyter Development Team contains an open redirect vulnerability.
Products Affected
- Jupyter Server versions 2.17.0 and earlier
Description
Jupyter Server provided by Jupyter Development Team contains the vulnerability listed below.
- Open redirect (CWE-601)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N Base Score 6.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N Base Score 7.4
- CVE-2025-61669
Impact
When accessing a specially crafted URL, the user may be redirected to an arbitrary website and become a victim of a phishing attack.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Jupyter Development Team | Open redirection vulnerability in `next` query parameter |
References
JPCERT/CC Addendum
The CVSS scores are based on the information of CVE-2025-61669 which was assigned to the vulnerability.
Vulnerability Analysis by JPCERT/CC
Credit
Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA and the developer.
JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000080 |