Configuration File Vulnerability in Jupyter Core on Windows Systems
CVE-2025-30167

7.3HIGH

Key Information:

Vendor

Jupyter

Vendor
CVE Published:
3 June 2025

What is CVE-2025-30167?

Jupyter Core, a foundational component for Jupyter projects, contains a vulnerability on Windows systems that can allow unauthorized users to create configuration files within the shared %PROGRAMDATA% directory. This security flaw affects systems where multiple users can access unprotected directories, leading to potential unauthorized configurations that could impact other users' environments. To mitigate this vulnerability, users should upgrade to Jupyter Core version 5.8.0 or later. Additional security measures include adjusting permissions on the %PROGRAMDATA% directory to restrict access or creating a dedicated %PROGRAMDATA%\jupyter directory with strict permissions.

Affected Version(s)

jupyter_core < 5.8.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.