PT-2026-30252 · Unknown · Jupyterhub
Fushuling
+1
·
Published
2026-04-03
·
Updated
2026-04-08
·
CVE-2026-33709
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JupyterHub versions prior to 5.4.4
Description
A flaw in JupyterHub allows attackers to create links that redirect users to a JupyterHub login page, and then to an attacker-controlled site instead of a legitimate JupyterHub page. This bypasses JupyterHub's security checks.
Recommendations
Upgrade to JupyterHub version 5.4.4.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyterhub