{"id":"GHSA-grfj-wjv9-4f9v","summary":"Open redirect in Jupyter Server","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nOpen redirect vulnerability - a maliciously crafted link to a jupyter server could redirect the browser to a different website.\n\nAll jupyter servers are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may *appear* safe, but ultimately redirect to a spoofed server on the public internet.\n\nThis originated in jupyter/notebook: https://github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqh\n\n### Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\njupyter_server 1.0.6\n\n### References\n\n[OWASP page on open redirects](https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html)\n\n### For more information\n\nIf you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [security@ipython.org](mailto:security@ipython.org).\n\nCredit: zhuonan li of Alibaba Application Security Team","aliases":["CVE-2020-26232","PYSEC-2020-234"],"modified":"2026-03-13T22:00:43.202217Z","published":"2020-11-24T21:20:52Z","related":["CVE-2020-26232"],"database_specific":{"nvd_published_at":null,"severity":"MODERATE","cwe_ids":["CWE-601"],"github_reviewed_at":"2020-11-24T21:10:20Z","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jupyter/jupyter_server/security/advisories/GHSA-grfj-wjv9-4f9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26232"},{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/commit/3d83e49090289c431da253e2bdb8dc479cbcb157"},{"type":"PACKAGE","url":"https://github.com/jupyter-server/jupyter_server"},{"type":"WEB","url":"https://github.com/jupyter-server/jupyter_server/blob/master/CHANGELOG.md#106---2020-11-18"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2020-234.yaml"}],"affected":[{"package":{"name":"jupyter-server","ecosystem":"PyPI","purl":"pkg:pypi/jupyter-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.6"}]}],"versions":["0.0.0","0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.1.0","0.1.1","0.2.0","0.2.1","0.3.0","1.0.0","1.0.0rc0","1.0.0rc1","1.0.0rc10","1.0.0rc11","1.0.0rc12","1.0.0rc13","1.0.0rc14","1.0.0rc15","1.0.0rc16","1.0.0rc2","1.0.0rc3","1.0.0rc4","1.0.0rc5","1.0.0rc6","1.0.0rc7","1.0.0rc8","1.0.0rc9","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-grfj-wjv9-4f9v/GHSA-grfj-wjv9-4f9v.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}