CVE Explorer
CVE-2026-44181
Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In versions 2.0.0rc2 and above, prior to 3.3.0, the environment variables (KERNEL_XXX) used during the rendering of the Kubernetes manifest are vulnerable to Server Side Template Injection (SSTI). By including Jinja2 template expressions it is possible to execution Python code and OS Commands in the Enterprise Gateway service. The code can use or steal
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"enterprise_gateway","vendor":"jupyter-server","versions":[{"status":"affected","version":">= 2.0.0rc2, < 3.3.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":10,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"HIGH","subIntegrityImpact":"HIGH","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/jupyter-server/enterprise_gateway/releases/tag/v3.3.0","tags":["x_refsource_MISC"],"url":"https://github.com/jupyter-server/enterprise_gateway/releases/tag/v3.3.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/cna/references/1
{"name":"https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-f49j-v924-fx9w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-f49j-v924-fx9w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/jupyter-server/enterprise_gateway/security/advisories/GHSA-f49j-v924-fx9w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:75e18379940c2622c8aacfcf2bb0d3036f6c6ebea7d8d61837e527d378d9a7d3 · sha256:d76a36db2dcfdab7… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.