GITHUBEXPLOIT 5.4 MEDIUM

Exploit for Cross-Site Request Forgery (CSRF) in Jupyter Jupyterhub_6DC85E25-562C-5013-9637-8ECC82BB80F9

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Description

CVE-2026-40864 — JupyterHub XSRF bypass via cross-origin form POST Sec-Fetch-Mode: no-cors Severity: Moderate CWE: CWE-352 — Cross-Site Request Forgery XSRF Affected: jupyterhub 4.1.0 ≤ version posting to a different origin — precisely the classic CSRF...
Visit Original Source

Basic Information

ID 6DC85E25-562C-5013-9637-8ECC82BB80F9
Published Jun 13, 2026 at 07:11

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.