Executive brief
Jupyter Server, the backend for Jupyter web applications, contains a vulnerability that allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can send them to a fake login page or a site hosting malware while making it appear as though the user is still on their trusted Jupyter domain. This is primarily used to steal login credentials or sensitive data through phishing.
Technical details
An open redirect vulnerability (CWE-601) exists in Jupyter Server due to insufficient validation in the 'LoginFormHandler._redirect_safe()' method. The 'next' URL query parameter fails to properly sanitize input, allowing an attacker to use a triple-slash prefix (e.g., '///google.com') to bypass internal redirection checks and force a redirect to an external domain. This can be exploited by sending a crafted URL to a user; if the user interacts with the link, they are redirected to an arbitrary site. The issue is fixed in Jupyter Server version 2.18.0.
Affected products
- Jupyter Project jupyter-server <= 2.17.0
Timeline
- 2026-05-05: disclosed
- 2026-05-05: advisory
- 2026-05-05: patched