StackRadar

CVE-2025-30167

High

Advisory

Published 4 Jun 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.3
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 1
affected package

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
jupyter-corepypi4.4.0, 4.6.3, 4.7.1, 4.9.1+6 more5.8.121
OSV records
GHSA-33p9-3p43-82vq
Also known as
PYSEC-2026-1477

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
jupyter-core@5.7.1
5.8.1

Open the chart page →

12,746
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
jupyter-core@4.6.3
5.8.1

Open the chart page →

52,919
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
jupyter-core@5.7.1
5.8.1

Open the chart page →

14,094
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
jupyter-core@4.4.0
5.8.1

Open the chart page →

36,094
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
jupyter-core@4.7.1
5.8.1

Open the chart page →

5,305
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
jupyter-core@4.4.0
5.8.1

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
jupyter-core@4.4.0
5.8.1

Open the chart page →

36,094
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
jupyter-core@5.7.2
5.8.1

Open the chart page →

16,604
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
jupyter-core@5.3.1
5.8.1

Open the chart page →

7,356
kyso-nbdimekyso1.0.01 of 1See more

kyso-nbdime kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
kyso/kyso-nbdime:latest4aa9d38ee81d
jupyter-core@5.1.0
5.8.1

Open the chart page →

2,765
nubladolsst-sqre0.9.233 of 5See more

nublado lsst-sqre 0.9.23

3 of the 5 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
lsstsqre/prepuller:latest19c2dfc4e4ff
jupyter-core@4.7.1
5.8.1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
jupyter-core@4.7.1
5.8.1
lsstsqre/wfdispatcher:lateste9feb99f524d
jupyter-core@4.7.1
5.8.1

Open the chart page →

5,786
smilencsaVerified publisher1.1.07 of 23See more

smile ncsa 1.1.0

7 of the 23 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
jupyter-core@5.3.2
5.8.1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
jupyter-core@4.12.0
5.8.1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
jupyter-core@4.12.0
5.8.1
socialmediamacroscope/classification_train:0.1.207477060bba8
jupyter-core@4.12.0
5.8.1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
jupyter-core@4.12.0
5.8.1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
jupyter-core@4.12.0
5.8.1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
jupyter-core@4.12.0
5.8.1

Open the chart page →

109,294
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-30167.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
jupyter-core@4.9.1
5.8.1

Open the chart page →

5,321

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aristidetm/basic-notebook:3.6.5469dbc951224
jupyter-core@5.7.2
5.8.1
1
cheyang/distributed-tf:1.6.046cc34755493
jupyter-core@4.4.0
5.8.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
jupyter-core@4.4.0
5.8.1
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
jupyter-core@5.3.1
5.8.1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
jupyter-core@4.6.3
5.8.1
1
kyso/kyso-nbdime:latest4aa9d38ee81d
jupyter-core@5.1.0
5.8.1
1
lsstsqre/prepuller:latest19c2dfc4e4ff
jupyter-core@4.7.1
5.8.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
jupyter-core@4.7.1
5.8.1
1
lsstsqre/wfdispatcher:lateste9feb99f524d
jupyter-core@4.7.1
5.8.1
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
jupyter-core@4.9.1
5.8.1
1
pangeo/base-notebook:2024.01.155fbe688a4f80
jupyter-core@5.7.1
5.8.1
1
robmarkcole/deepstack-ui:latest410275726459
jupyter-core@4.7.1
5.8.1
1
socialmediamacroscope/autophrase:0.1.570fb11d4f531
jupyter-core@5.3.2
5.8.1
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
jupyter-core@4.12.0
5.8.1
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
jupyter-core@4.12.0
5.8.1
1
socialmediamacroscope/classification_train:0.1.207477060bba8
jupyter-core@4.12.0
5.8.1
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
jupyter-core@4.12.0
5.8.1
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
jupyter-core@4.12.0
5.8.1
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
jupyter-core@4.12.0
5.8.1
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
jupyter-core@4.4.0
5.8.1
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
jupyter-core@5.7.1
5.8.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.