—
PYSEC-2022-42974
Quick fix
PYSEC-2022-42974 — jupyter-core: upgrade to the fixed version with the command below.
pip install --upgrade 'jupyter-core>=1118c8ce01800cb689d51f655f5ccef19516e283'Details
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/jupyter-core
Introduced in:
0Fixed in: 1118c8ce01800cb689d51f655f5ccef19516e283Fix
pip install --upgrade 'jupyter-core>=1118c8ce01800cb689d51f655f5ccef19516e283'