VDB
Sign up
—

PYSEC-2026-365

TigerVNC accessible via the network and not just via a UNIX socket as intended

Quick fix

PYSEC-2026-365 — jupyter-remote-desktop-proxy: upgrade to the fixed version with the command below.

pip install --upgrade 'jupyter-remote-desktop-proxy>=3.0.1'

Details

## Summary

`jupyter-remote-desktop-proxy` was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by `jupyter-remote-desktop-proxy` were still accessible via the network.

This vulnerability does not affect users having TurboVNC as the `vncserver` executable.

## Credits

This vulnerability was identified by Arne Gottwald at University of Göttingen and analyzed, reported, and reviewed by @frejanordsiek.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/jupyter-remote-desktop-proxy
Introduced in: 3.0.0Fixed in: 3.0.1
Fixpip install --upgrade 'jupyter-remote-desktop-proxy>=3.0.1'

References