Executive brief
nbviewer is a web application that renders Jupyter Notebooks as static web pages. A path traversal vulnerability in the LocalFileHandler component allows attackers to read files outside the configured root directory, potentially exposing sensitive notebooks and credentials stored on the same server.
Technical details
The vulnerability exists in LocalFileHandler.can_show() which validates file paths using string-prefix comparison rather than proper path normalization and canonical path checking. An attacker can craft requests with paths that share the root directory as a textual prefix (e.g., if root is "/notebooks", requesting "/notebooks_sibling/file" bypasses validation). The flaw affects only the local file provider handler and requires network access to the nbviewer instance. An attacker can read arbitrary files accessible to the nbviewer process, including sensitive configuration and credential files. This is fixed in versions after 1.0.1.
Affected products
- Jupyter nbviewer through 1.0.1
Timeline
- 2026-09-06: disclosed