Executive brief
Jupyter Server, a core component for running Jupyter interactive notebooks, contains a security flaw in how it validates web requests. An attacker can trick the server into accepting malicious requests by using a domain name that starts with a trusted name but ends in a malicious one (e.g., trusted.example.com.evil.com). If exploited, this could allow an attacker to steal sensitive data, perform unauthorized actions, or potentially execute malicious code on the user's system.
Technical details
A vulnerability exists in jupyter-server (versions 1.12.0 through 2.17.0) due to improper validation of the Origin header when the `allow_origin_pat` configuration is active. The server uses Python's `re.match()` function, which only anchors the regular expression at the beginning of the string. This allows an attacker to bypass security checks by using a subdomain they control that begins with a legitimate, trusted domain string (e.g., `trusted.example.com.attacker.com`). The flaw impacts CORS headers, WebSocket connections, referer validation, and login redirects. Successful exploitation requires a user to visit a malicious site (User Interaction) and can result in sensitive data exposure or arbitrary code execution via compromised WebSocket communication.
Affected products
- Jupyter jupyter-server 1.12.0 - 2.17.0
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory