GPU VulnDB

Database/AI/ML frameworks & serving

Jupyter Server: login `next` parameter allows redirect to an arbitrary external host

CVSS 6.3CVE-2025-61669AI/ML frameworks & servingcurated

Impact

A crafted login URL for a Jupyter Server instance sends the user to an attacker-controlled site after - or instead of - authenticating. On a GPU fleet the notebook endpoint is usually the one URL researchers are trained to trust and bookmark, so a redirect that keeps the real hostname in the link is a credible way to harvest notebook credentials or tokens, which in turn grant code execution on a GPU node. No data is read and no code runs on the server itself; the whole impact is phishing leverage and it needs the user to click and then act on the destination page. Affects jupyter_server through 2.17.0.

Who can reach it

Anyone who can get a user to open a URL pointing at a reachable Jupyter Server login page. No authentication needed to craft the link; the victim must click it.

What to do

Upgrade jupyter_server to 2.18.0 and restart the notebook service. Cheap where notebooks run as per-user pods or a managed JupyterHub image - rebuild the image and restart sessions; no node drain or reboot. Running sessions are interrupted when the server restarts, so warn users or roll it with their next session.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.