CVE-2026-39377

EUVD-2026-24023
The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions 6.5 through 7.17.0 allow arbitrary file writes to locations outside the intended output directory when processing notebooks containing crafted cell attachment filenames. The `ExtractAttachmentsPreprocessor` passes attachment filenames directly to the filesystem without sanitization, enabling path traversal attacks. This vulnerability provides complete control over both the destination path and file extension. Version 7.17.1 contains a patch.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 18.27%
Affected Products (NVD)
VendorProductVersion
jupyternbconvert
6.5.0 ≤
𝑥
< 7.17.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nbconvert
bookworm
6.5.3-3
fixed
bullseye
not-affected
forky
7.17.1-2
fixed
sid
7.17.1-2
fixed
trixie
7.16.6-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nbconvert
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage