Database/AI/ML frameworks & serving
Jupyter Server: Path traversal in the REST API
CVE-2026-35397AI/ML frameworks & servingcurated
Impact
Path traversal in the REST API
Who can reach it
Notebook user or anyone reaching an exposed notebook port
What to do
Upgrade past 2.17.0. Notebook servers on GPU nodes are frequently exposed with token auth only
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.