Configuration File Vulnerability in Jupyter Core on Windows Systems
CVE-2025-30167
What is CVE-2025-30167?
Jupyter Core, a foundational component for Jupyter projects, contains a vulnerability on Windows systems that can allow unauthorized users to create configuration files within the shared %PROGRAMDATA% directory. This security flaw affects systems where multiple users can access unprotected directories, leading to potential unauthorized configurations that could impact other users' environments. To mitigate this vulnerability, users should upgrade to Jupyter Core version 5.8.0 or later. Additional security measures include adjusting permissions on the %PROGRAMDATA% directory to restrict access or creating a dedicated %PROGRAMDATA%\jupyter directory with strict permissions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jupyter_core < 5.8.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
