CVE-2026-86258 nbviewer through 1.0.1 contains a path traversal… — CVE Notify — TG.ME

🚨 CVE-2026-86258
nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outside the configured root by requesting paths that share the root as a textual prefix, disclosing unintended notebooks and credentials.

🎖@cveNotify
GitHub
GitHub - jupyter/nbviewer: nbconvert as a web service: Render Jupyter Notebooks as static web pages
nbconvert as a web service: Render Jupyter Notebooks as static web pages - jupyter/nbviewer
September 6, 2026 56