Junglewise Threat Intelligence

CVE-2026-39378: nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

CVE-2026-39378 · Severity: medium · CVSS 6.5 · Published 2026-04-21

Technologies: nbconvert (PyPI). Vendors: PyPI.

Executive brief

## Summary

When `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML.

## Patches

Upgrade to nbconvert 7.17.1

## Workarounds

Do not enable `HTMLExporter.embed_images` (it is not enabled by default).

Affected products

  • PyPI nbconvert

References

Related threats