Cross-site scripting in Jupyter Server - CVE-2026-44727
Published: September 3, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to cross-site scripting in NbconvertFileHandler and NbconvertPostHandler when rendering user-authored notebook HTML under the Jupyter origin without a sandbox directive in the Content-Security-Policy. A local user can place crafted HTML payloads in a notebook display_data output to execute arbitrary code.
User interaction is required because an authenticated victim must navigate to a /nbconvert/html/<path> view containing attacker-authored output.
Affected software
Fedora
python-jupyter-server
How to mitigate CVE-2026-44727
python-jupyter-server - update to 2.20.0-1.fc43