Jupyter Core Uncontrolled Search Path Element Local Privilege Escalation Vulnerability on Windows

Vulnerability

A local privilege escalation vulnerability has been identified in Jupyter Core versions prior to 5.8.0, specifically on Windows. The issue arises because the shared %PROGRAMDATA% directory is searched for configuration files, which may allow users to create files that affect other users. This vulnerability only impacts shared Windows systems with multiple users and unprotected %PROGRAMDATA% directories.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a user to gain elevated rights or access on the system.

Remediation

Users should upgrade to Jupyter Core version 5.8.1 or later. For those using Jupyter Server, note that version 5.8.0 is patched but may cause compatibility issues. Alternatively, administrators can modify the permissions on the %PROGRAMDATA% directory to prevent unauthorized write access, create the %PROGRAMDATA%\jupyter directory with restrictive permissions, or set the %PROGRAMDATA% environment variable to a directory with appropriate permissions.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.6
exploitability
3.3
remediation
8.3
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.