Skip to content

Fix CVE-2025-30167: upgrade jupyter_core from 5.3.1 to 5.8.1#6

Merged
ehabets merged 1 commit intomasterfrom
claude/fix-dependabot-security-mu5pq
Feb 25, 2026
Merged

Fix CVE-2025-30167: upgrade jupyter_core from 5.3.1 to 5.8.1#6
ehabets merged 1 commit intomasterfrom
claude/fix-dependabot-security-mu5pq

Conversation

@ehabets
Copy link
Copy Markdown
Member

@ehabets ehabets commented Feb 25, 2026

Resolves Dependabot alert #17 (GHSA-33p9-3p43-82vq / CVE-2025-30167): jupyter_core < 5.8.0 has a local privilege escalation vulnerability on Windows via uncontrolled search path in %PROGRAMDATA% for config files.

https://claude.ai/code/session_019g4QCLqBAwnDnGgKEG2PnU

Resolves Dependabot alert #17 (GHSA-33p9-3p43-82vq / CVE-2025-30167):
jupyter_core < 5.8.0 has a local privilege escalation vulnerability on
Windows via uncontrolled search path in %PROGRAMDATA% for config files.

https://claude.ai/code/session_019g4QCLqBAwnDnGgKEG2PnU
@ehabets ehabets merged commit d464a10 into master Feb 25, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants