Database/AI/ML frameworks & serving
jupyter-lsp: Unauthenticated file read/write through the LSP extension
CVSS 7.3CVE-2024-22415AI/ML frameworks & servingcurated
Impact
Unauthenticated file read/write through the LSP extension
Who can reach it
Network attacker reaching JupyterLab
What to do
Upgrade; the extension bypasses notebook auth
References
Related entries
- SGLang (`/update_weights_from_tensor`): Unsafe deserialization of the `serialized_named_tensors` argumentCVE-2025-10164 · SGLang (`/update_weights_from_tensor`)High
- Jupyter Core (Windows): Config read from a shared writable pathCVE-2025-30167 · Jupyter Core (Windows)High
- llama-index-core: Predictable hardcoded cache directoryCVE-2025-7647 · llama-index-coreHigh
- Keras (HDF5 path): Code execution from crafted `.h5`/`.hdf5` model despite safe modeCVE-2025-9905 · Keras (HDF5 path)High
- Keras: Code execution from crafted `.keras` archive despite safe modeCVE-2025-9906 · KerasHigh
- MLflow (artifact handler): Directory traversalCVE-2026-2033 · MLflow (artifact handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.