CVE-2025-30167: Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Published Jun 3, 2025
·
Updated

Impact

On Windows, the shared %PROGRAMDATA% directory is searched for configuration files (SYSTEMCONFIGPATH and SYSTEMJUPYTERPATH), which may allow users to create configuration files affecting other users.

Only shared Windows systems with multiple users and unprotected %PROGRAMDATA% are affected.

Mitigations

- upgrade to jupytercore>=5.8.1 (5.8.0 is patched but breaks jupyter-server) , or - as administrator, modify the permissions on the %PROGRAMDATA% directory so it is not writable by unauthorized users, or - as administrator, create the %PROGRAMDATA%\jupyter directory with appropriately restrictive permissions, or - as user or administrator, set the %PROGRAMDATA% environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators or the current user)

Credit

Reported via Trend Micro Zero Day Initiative as ZDI-CAN-25932

Other sources

Jupyter Core is a package for the core common functionality of Jupyter projects. When using Jupyter Core prior to version 5.8.0 on Windows, the shared %PROGRAMDATA% directory is searched for configuration files (SYSTEMCONFIGPATH and SYSTEMJUPYTERPATH), which may allow users to create configuration files affecting other users. Only shared Windows systems with multiple users and unprotected %PROGRAMDATA% are affected. Users should upgrade to Jupyter Core version 5.8.0 or later to receive a patch. Some other mitigations are available. As administrator, modify the permissions on the %PROGRAMDATA% directory so it is not writable by unauthorized users; or as administrator, create the %PROGRAMDATA%\jupyter directory with appropriately restrictive permissions; or as user or administrator, set the %PROGRAMDATA% environment variable to a directory with appropriately restrictive permissions (e.g. controlled by administrators or the current user).

MITRE

Affected Software

13 affected componentsFixes available
Project Jupyter Jupyter Core<5.8.0
pip/jupyter_core<5.8.0
5.8.1
jupyter Jupyter Core<5.8.0
IBM Cognos Analytics<=11.2.0
IBM Cognos Analytics<=12.0
IBM Cognos Transformer<=12.0
IBM Cognos Transformer<=11.2.4
IBM Cognos Transformer<=12.1.0
IBM Cognos Analytics<=11.2.0
IBM Cognos Analytics<=12.1.0
IBM Cognos Analytics<=12.0
IBM Cognos Transformer<=11.2.4
IBM Cognos Transformer<=12.1.0

Event History

Jun 3, 2025
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
Affected Software
Jun 4, 2025
Advisory Published
via GitHub·09:00 PM
Data Sourced
via GitHub·09:00 PM
DescriptionSeverityWeaknessAffected Software
May 26, 2026
Data Sourced
via IBM·05:05 PM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30167?

CVE-2025-30167 has been assessed to have a moderate severity due to the potential exposure of sensitive configuration files in shared directories.

2

How do I fix CVE-2025-30167?

To fix CVE-2025-30167, update Jupyter Core to version 5.8.0 or later.

3

What versions of Jupyter Core are affected by CVE-2025-30167?

CVE-2025-30167 affects Jupyter Core versions prior to 5.8.0.

4

What platforms are impacted by CVE-2025-30167?

CVE-2025-30167 specifically impacts the Windows platform.

5

Who is the vendor for CVE-2025-30167?

The vendor for CVE-2025-30167 is Project Jupyter.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203