MEDIUM4.3
PYSEC-2026-1312
DockerSpawner allows any image by default
Quick fix
PYSEC-2026-1312 — dockerspawner: upgrade to the fixed version with the command below.
pip install --upgrade 'dockerspawner>=13.0.0'Details
### Impact
Users of JupyterHub deployments running DockerSpawner starting with 0.11.0 without specifying `DockerSpawner.allowed_images` configuration allow users to launch _any_ pullable image, instead of restricting to only the single configured image, as intended.
### Patches
Upgrade to DockerSpawner 13.
### Workarounds
Explicitly setting `DockerSpawner.allowed_images` to a non-empty list containing only the default image will result in the intended default behavior:
```python c.DockerSpawner.image = "your-image" c.DockerSpawner.allowed_images = ["your-image"] ```
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/dockerspawner
Introduced in:
0.11.0Fixed in: 13.0.0Fix
pip install --upgrade 'dockerspawner>=13.0.0'References
- https://github.com/jupyterhub/dockerspawner/security/advisories/GHSA-hfgr-h3vc-p6c2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48311[ADVISORY]
- https://github.com/jupyterhub/dockerspawner/commit/3ba4b665b6ca6027ea7a032d7ca3eab977574626[WEB]
- https://github.com/jupyterhub/dockerspawner[PACKAGE]
- https://pypi.org/project/dockerspawner[PACKAGE]
- https://github.com/advisories/GHSA-hfgr-h3vc-p6c2[ADVISORY]