CVE-2020-26215

unknown
Published 2020-11-18 · Modified 2025-10-09
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:L
CVSS v2
VIR risk

Description

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may appear safe, but ultimately redirect to a spoofed server on the public internet. The issue is patched in version 6.1.5.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2020-26215

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed6.1.5-1
debian debianbullseyefixed6.1.5-1
debian debianforkyfixed6.1.5-1
debian debiansidfixed6.1.5-1
debian debiantrixiefixed6.1.5-1

Package impact

EcosystemPackageVulnerableFixed
python PyPInotebook<6.1.56.1.5
python PyPInotebook<3cec4bbe21756de9f0c4bccf18cf61d840314d74||<6.1.53cec4bbe21756de9f0c4bccf18cf61d840314d74

References

Verify integrity in audit chain (admin only). AS-IS.