{"id":"GHSA-4c99-qj7h-p3vg","summary":"nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames","details":"# Arbitrary File Write via Path Traversal in Cell Attachment Filenames\n\n## Summary\n\nnbconvert allows arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `ExtractAttachmentsPreprocessor` passes attachment filenames directly to the filesystem without sanitization, enabling path traversal attacks. This vulnerability provides complete control over both the destination path and file extension.\n\n\n## Impact\n\nThis vulnerability allows writing files with arbitrary content to arbitrary filesystem locations, limited only by the permissions of the process running nbconvert. The attacker controls:\n- Full destination path (via `../` traversal)\n- Filename\n- File extension\n- File content\n\n## Patches\n\n- upgrade to nbconvert v7.17.1\n\n## Workarounds\n\ndisable ExtractAttachmentsPreprocessor by setting:\n\n```python\nc. ExtractAttachmentsPreprocessor.enabled = False\n```","aliases":["CVE-2026-39377","PYSEC-2026-2229"],"modified":"2026-09-10T03:51:00.940697146Z","published":"2026-04-21T17:18:18Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-04-21T17:18:18Z","nvd_published_at":"2026-04-21T01:16:05Z","cwe_ids":["CWE-22","CWE-73"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-39377"},{"type":"PACKAGE","url":"https://github.com/jupyter/nbconvert"},{"type":"WEB","url":"https://github.com/jupyter/nbconvert/releases/tag/v7.17.1"}],"affected":[{"package":{"name":"nbconvert","ecosystem":"PyPI","purl":"pkg:pypi/nbconvert"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.5.0"},{"fixed":"7.17.1"}]}],"versions":["6.5.0","6.5.1","6.5.2","6.5.3","6.5.4","7.0.0","7.0.0rc0","7.0.0rc1","7.0.0rc2","7.0.0rc3","7.1.0","7.10.0","7.11.0","7.12.0","7.13.0","7.13.1","7.14.0","7.14.1","7.14.2","7.15.0","7.16.0","7.16.1","7.16.2","7.16.3","7.16.4","7.16.5","7.16.6","7.17.0","7.2.0","7.2.1","7.2.10","7.2.2","7.2.3","7.2.4","7.2.5","7.2.6","7.2.7","7.2.8","7.2.9","7.3.0","7.3.1","7.4.0","7.5.0","7.6.0","7.7.0","7.7.1","7.7.2","7.7.3","7.7.4","7.8.0","7.9.0","7.9.1","7.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-4c99-qj7h-p3vg/GHSA-4c99-qj7h-p3vg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}