CVE-2025-61669Disclosure(jupyter / jupyter_server)

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch jupyter jupyter_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._redirect_safe()`, which allows redirects to arbitrary external domains via values such as `///example.com`. An attacker can use a crafted login URL to redirect users to a malicious site and facilitate phishing attacks. This issue is fixed in version 2.18.0.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jupyter_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-11); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
jupyter_server

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-11: 1Mentions · 2026-05-28: 1Active Exploitation · 2026-05-28: 1Patch / Workaround · 2026-05-28: 1Technical Details · 2026-05-28: 105-1105-28
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-111
Disclosure1
2026-05-281
Patch1
Full discourse2 posts
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Patch

    今日まとめたのは13本。半分がパッチで止められる傷、残りはもう悪用が始まっているか、4年潜伏していた古傷だ。「うちは関係ない」で読み飛ばすな。 ・三菱電機GX Works3など複数FA製品、CVSS8.3のRCE ・Jupyter Server CVE-2025-61669、フィッシング踏み台に ・Ubiquiti UniFi OS、遠隔影響のクリティカル脆弱性 ・IBM ELMのJazz Foundationに脆弱性、パッチ公開 ・Veeamバックアップ製品に脆弱性、修正版公開 ・Google Cloud Apigee SSRF、認証トークン窃取の恐れ ・FortiClient EMS CVE-2026-35616悪用、EKZ infostealer拡散 ・Gitea CVE-2026-27771、4年未検出・3万超デプロイに影響 ・Carnival Cruise、ShinyHunters侵害で600万人流出を公式認定 ・Glassworm、ブロックチェーンC2を解体され制圧 ・FBI警告、Silent Ransom Groupが法律事務所に物理侵入 ・GPUマイナー、SEO汚染とAIチャットボット推奨経由で拡散 ・IPA、5ヶ月指名停止で独法の脆弱性監査が停止 パッチで止まる傷と、もう手遅れの傷が同じ日に並んでいる。君の現場で今夜、最初に手を付けるべき1本はどれだ?

    Post summary

    The post enumerates 13 CVEs, noting which have patches available and which are already being exploited in the wild, urging readers to prioritize remediation.

    00012850
    498 followersView on X
  • niwasaki@iwasakinoriaki
    Disclosure

    Jupyter に報告した脆弱性 CVE-2025-61669 が公開されました。 https://www.cve.org/CVERecord?id=CVE-2025-61669

    Post summary

    The text announces that CVE‑2025‑61669, reported to Jupyter, has now been publicly disclosed through the CVE record, with no further technical or exploit details provided.

    00000720
    402 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjupyterjupyter_server---

Explore more