Configuration File Vulnerability in Jupyter Core on Windows Systems
CVE-2025-30167
7.3HIGH
What is CVE-2025-30167?
Jupyter Core, a foundational component for Jupyter projects, contains a vulnerability on Windows systems that can allow unauthorized users to create configuration files within the shared %PROGRAMDATA%
directory. This security flaw affects systems where multiple users can access unprotected directories, leading to potential unauthorized configurations that could impact other users' environments. To mitigate this vulnerability, users should upgrade to Jupyter Core version 5.8.0 or later. Additional security measures include adjusting permissions on the %PROGRAMDATA%
directory to restrict access or creating a dedicated %PROGRAMDATA%\jupyter
directory with strict permissions.
Affected Version(s)
jupyter_core < 5.8.0