{"id":"PYSEC-2026-1477","summary":"Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability","details":"## Impact\n\nOn Windows, the shared `%PROGRAMDATA%` directory is searched for configuration files (`SYSTEM_CONFIG_PATH` and `SYSTEM_JUPYTER_PATH`), which may allow users to create configuration files affecting other users.\n\nOnly shared Windows systems with multiple users and unprotected `%PROGRAMDATA%` are affected.\n\n## Mitigations\n\n- upgrade to `jupyter_core\u003e=5.8.1` (5.8.0 is patched but breaks `jupyter-server`) , or\n- as administrator, modify the permissions on the `%PROGRAMDATA%` directory so it is not writable by unauthorized users, or\n- as administrator, create the `%PROGRAMDATA%\\jupyter` directory with appropriately restrictive permissions, or\n- as user or administrator, set the `%PROGRAMDATA%` environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators _or_ the current user)\n\n## Credit\n\nReported via Trend Micro Zero Day Initiative as ZDI-CAN-25932","aliases":["CVE-2025-30167","GHSA-33p9-3p43-82vq"],"modified":"2026-07-07T17:46:46.038225137Z","published":"2026-07-07T16:02:53.654510Z","references":[{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/security/advisories/GHSA-33p9-3p43-82vq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30167"},{"type":"WEB","url":"https://github.com/jupyter/jupyter_core/commit/5e8965600adda6b416692ce7e85ecb2bd814bd52"},{"type":"PACKAGE","url":"https://github.com/jupyter/jupyter_core"},{"type":"PACKAGE","url":"https://pypi.org/project/jupyter-core"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-33p9-3p43-82vq"}],"affected":[{"package":{"name":"jupyter-core","ecosystem":"PyPI","purl":"pkg:pypi/jupyter-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.8.1"}]}],"versions":["4.0.0","4.0.0.dev","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.1.0","4.1.1","4.10.0","4.11.0","4.11.1","4.11.2","4.12.0","4.2.0","4.2.1","4.3.0","4.4.0","4.5.0","4.6.0","4.6.1","4.6.2","4.6.3","4.7.0","4.7.0rc0","4.7.1","4.8.0","4.8.0b0","4.8.0rc0","4.8.0rc1","4.8.1","4.8.2","4.9.0","4.9.0rc0","4.9.1","4.9.1rc0","4.9.2","5.0.0","5.0.0rc0","5.0.0rc1","5.0.0rc2","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.2.0","5.3.0","5.3.1","5.3.2","5.4.0","5.5.0","5.5.1","5.6.0","5.6.1","5.7.0","5.7.1","5.7.2","5.8.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/jupyter-core/PYSEC-2026-1477.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}