Published:2026/05/28  Last Updated:2026/05/28

JVN#01719116
Jupyter Server vulnerable to open redirect

Overview

Jupyter Server provided by Jupyter Development Team contains an open redirect vulnerability.

Products Affected

  • Jupyter Server versions 2.17.0 and earlier

Description

Jupyter Server provided by Jupyter Development Team contains the vulnerability listed below.

  • Open redirect (CWE-601)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N Base Score 6.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N Base Score 7.4
    • CVE-2025-61669

Impact

When accessing a specially crafted URL, the user may be redirected to an arbitrary website and become a victim of a phishing attack.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Jupyter Development Team Open redirection vulnerability in `next` query parameter

References

JPCERT/CC Addendum

The CVSS scores are based on the information of CVE-2025-61669 which was assigned to the vulnerability.

Vulnerability Analysis by JPCERT/CC

Credit

Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA and the developer.
JPCERT/CC coordinated with the developer to publish the advisory under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000080