« Volver al listado

CVE-2026-35397

Estado: ModificadaAlta (7.6)—

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named "test", the API permits access to a sibling directory named "testtest" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can read, write, and delete files in affected sibling directories.

Leer descripción completaMostrar menos

Multi-tenant deployments using predictable naming schemes are particularly at risk, as a user with a directory named "user1" could access directories for user10 through user19 and beyond. A user who can choose a single-character folder name could gain access to a significant number of sibling directories.

Version 2.18.0 contains a fix. As a workaround, ensure folder names do not share a common prefix with any sibling directory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N, PR:L sin UI:R apunta a T1210 (servicios remotos con privilegios). El atacante autenticado abusa de path traversal en /api/contents para leer, escribir y eliminar archivos en directorios sibling, cumpliendo con T1005 (lectura de datos) y manipulación/eliminación (T1565.002, T1485).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-35397",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-35397",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-06T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Secondary",
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 1.6
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 7.6,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "jupyter-server",
          "product": "jupyter_server",
          "versions": [
            {
              "status": "affected",
              "version": "< 2.18.0"
            }
          ]
        }
      ]
    },
    {
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:migration_toolkit_applications:8.2::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Migration Toolkit for Applications 8.2",
          "versions": [
            {
              "status": "unaffected",
              "version": "1784109883",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "mta/mta-solution-server-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787076778",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-th06-cpu-torch210-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787077779",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-th06-cuda130-torch210-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787076481",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-th06-rocm64-torch291-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787074331",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073913",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787074078",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073929",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073605",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073546",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073717",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073713",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai:3.4::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI 3.4",
          "versions": [
            {
              "status": "unaffected",
              "version": "1787073593",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "packageName": "rhoai/odh-th06-cpu-torch291-py312-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "packageName": "rhoai/odh-th06-cuda130-torch291-py312-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openshift_ai"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenShift AI (RHOAI)",
          "packageName": "rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-05-05T20:16:38.223",
  "references": [
    {
      "url": "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:43038",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:60520",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-35397",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2466858",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    },
    {
      "url": "https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-5789-5fc7-67v3",
      "tags": [
        "Exploit",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35397.json",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_dir and access sibling directories whose names begin with the same prefix as the root_dir. For example, with a root_dir named \"test\", the API permits access to a sibling directory named \"testtest\" through a crafted request to the /api/contents endpoint using encoded path components. An attacker can read, write, and delete files in affected sibling directories. Multi-tenant deployments using predictable naming schemes are particularly at risk, as a user with a directory named \"user1\" could access directories for user10 through user19 and beyond. A user who can choose a single-character folder name could gain access to a significant number of sibling directories. \n\nVersion 2.18.0 contains a fix. As a workaround, ensure folder names do not share a common prefix with any sibling directory."
    },
    {
      "lang": "es",
      "value": "Jupyter Server es el backend para las aplicaciones web de Jupyter. En las versiones 2.17.0 y anteriores, una vulnerabilidad de salto de ruta en la API REST permite a un usuario autenticado escapar del 'root_dir' configurado y acceder a directorios hermanos cuyos nombres comienzan con el mismo prefijo que el 'root_dir'. Por ejemplo, con un 'root_dir' llamado  test , la API permite el acceso a un directorio hermano llamado  testtest  a través de una solicitud manipulada al endpoint '/api/contents' utilizando componentes de ruta codificados. Un atacante puede leer, escribir y eliminar archivos en los directorios hermanos afectados. Las implementaciones multi-inquilino que utilizan esquemas de nombres predecibles están particularmente en riesgo, ya que un usuario con un directorio llamado  user1  podría acceder a los directorios de user10 a user19 y más allá. Un usuario que puede elegir un nombre de carpeta de un solo carácter podría obtener acceso a un número significativo de directorios hermanos.\n\nLa versión 2.18.0 contiene una corrección. Como solución alternativa, asegúrese de que los nombres de las carpetas no compartan un prefijo común con ningún directorio hermano."
    }
  ],
  "lastModified": "2026-08-28T16:17:45.870",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E0B6C703-7E28-4F23-9878-E157975C32A4",
              "versionEndExcluding": "2.18.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}