PT-2026-33878 · Jupyter · Nconvert
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-39377
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The
ExtractAttachmentsPreprocessor passes attachment filenames directly to the filesystem without sanitization, enabling path traversal attacks. This vulnerability provides complete control over both the destination path and file extension. Version 7.17.1 contains a patch.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nconvert