CVE-2026-39377General(jupyter / nbconvert)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jupyter nbconvert systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `ExtractAttachmentsPreprocessor` passes attachment filenames directly to the filesystem without sanitization, enabling path traversal attacks. This vulnerability provides complete control over both the destination path and file extension. Version 7.17.1 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nbconvert

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-21); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
nbconvert

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-21: 1Mentions · 2026-04-28: 1Mentions · 2026-05-11: 1Mentions · 2026-08-22: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-28: 104-2104-2805-1108-22
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-211
General1
2026-04-281
Disclosure1
2026-05-111
Patch1
2026-08-221
General1
Full discourse4 posts
  • Hugo Cesar Ramos@slackces
    General

    Ejecución de código malicioso Movimiento lateral CVE-2026-39377 https://t.co/509HhtYpqa

    Post summary

    The post flags CVE‑2026‑39377 as enabling malicious code execution and lateral movement, but offers no detailed technical, patch or exploit information.

    0000043
    5 followersView on X
  • RazzReport@RazzReport
    Patch

    OpenHands/OpenHands patched CVE-2026-44897 and CVE-2026-39377 for critical security. Concurrently, Significant-Gravitas/AutoGPT added 5-part concurrent task queues, addressing throughput in autonomous agent execution. ---

    Post summary

    The post announces that OpenHands/OpenHands has released patches for CVE‑2026‑44897 and CVE‑2026‑39377, highlighting security remediation.

    0000036
    8 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-39377: CVE-2026-39377: Arbitrary File Write via Path Traversal in Jupyter nbconvert Jupyter nbconvert versions 6.5 through 7.17.0 contain a path traversal vulnerability resulting in arbitrary file write capabilities. The `ExtractAttachmentsPr... https://cvereports.com/reports/CVE-2026-39377

    Post summary

    A new path‑traversal vulnerability (CVE‑2026‑39377) that allows arbitrary file writes has been disclosed for Jupyter nbconvert versions 6.5–7.17.0; no PoC, exploit, patch, or active exploitation details are provided.

    0000024
    36 followersView on X
  • DailyCVE@dailycve
    General

    🟠 nbconvert, Arbitrary File Write via Path Traversal, #CVE-2026-39377 (Moderate) https://dailycve.com/nbconvert-arbitrary-file-write-via-path-traversal-cve-2026-39377-moderate/

    Post summary

    The post announces CVE‑2026‑39377 affecting nbconvert, describing a path‑traversal based file write, but offers no details on exploitation, patches, or support code.

    0000026
    183 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjupyternbconvert-python-

Explore more