Open redirect in jupyterhub - CVE-2026-33709
Published: April 28, 2026
jupyterhub
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to an arbitrary attacker-controlled site.
The vulnerability exists due to url redirection to an untrusted site in the JupyterHub login redirect handling when processing crafted links. A remote attacker can construct a crafted link to redirect users to an arbitrary attacker-controlled site.
User interaction is required to click the crafted link.