PT-2025-23640 · Unknown · Jupyter Core

Minrk

·

Published

2025-02-13

·

Updated

2026-01-23

·

CVE-2025-30167

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jupyter Core versions prior to 5.8.0
Description The issue affects Jupyter Core on Windows, where the shared %PROGRAMDATA% directory is searched for configuration files, potentially allowing users to create files that impact other users. This is specifically a concern for shared Windows systems with multiple users and an unprotected %PROGRAMDATA% directory.
Recommendations For versions prior to 5.8.0, upgrade to Jupyter Core version 5.8.0 or later. As an administrator, modify the permissions on the %PROGRAMDATA% directory to prevent unauthorized write access. As an administrator, create the %PROGRAMDATA%jupyter directory with restrictive permissions. As a user or administrator, set the %PROGRAMDATA% environment variable to a directory with restrictive permissions, such as one controlled by administrators or the current user.

Exploit

Fix

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2025-06495
CVE-2025-30167
GHSA-33P9-3P43-82VQ
OPENSUSE-SU-2025:15272-1
ZDI-25-339

Affected Products

Jupyter Core