ZDI-CAN-25932: ZDI-25-339: JupyterLab Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of JupyterLab. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Additionally, the vulnerability is triggered only when a target user makes use of the product. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2025-30167.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25932?
ZDI-CAN-25932 has been classified as a critical severity vulnerability due to its privilege escalation capabilities.
How do I fix ZDI-CAN-25932?
To fix ZDI-CAN-25932, ensure you update JupyterLab to the latest version where the vulnerability has been patched.
Who is affected by ZDI-CAN-25932?
All installations of JupyterLab are affected if they allow local attackers to execute low-privileged code.
What type of vulnerability is ZDI-CAN-25932?
ZDI-CAN-25932 is a privilege escalation vulnerability that allows local attackers to gain higher system access.
Can ZDI-CAN-25932 be exploited remotely?
No, ZDI-CAN-25932 requires local access to the system for exploitation.