PT-2022-6759 · Unknown+5 · Jupyter Core+5

Published

2022-10-26

·

Updated

2025-10-20

·

CVE-2022-39286

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Jupyter Core versions prior to 4.11.2
Description The issue is related to arbitrary code execution in jupyter core due to the execution of untrusted files in the current working directory. This allows one user to run code as another, potentially leading to the disclosure of protected information and the upload and execution of code with elevated privileges.
Recommendations To resolve the issue, upgrade to Jupyter Core version 4.11.2 or later. As a temporary workaround, consider restricting access to the jupyter core functionality until a patch is applied. Avoid executing untrusted files in the current working directory to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-7854
BDU:2023-04040
CVE-2022-39286
DLA-3195-1
DSA-5422-1
GHSA-M678-F26J-3HRP
MGASA-2023-0062
PYSEC-2022-42974
USN-6153-1

Affected Products

Alt Linux
Astra Linux
Jupyter Core
Linuxmint
Red Os
Ubuntu