CVE-2026-86258: Schwachstellen-Eintrag (NVD)
nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the root as a textual prefix, disclosing unintended notebooks and credentials.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-06 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-86258 | Jupyter nbviewer up to 1.0.1 LocalFileHandler LocalFileHandler.can_show path traversal (EUVD-2026-72125)
A vulnerability marked as problematic has been reported in Jupyter nbviewer up to 1.0.1. Affected is the function LocalFileHandler.can_show of the component LocalFileHandler. The manipulation leads to path traversal. This vulnerability is d