StackRadar

CVE-2025-53000

High

Advisory

Published 18 Dec 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.5
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
nbconvertpypi5.3.1, 6.0.7, 6.1.0, 6.3.0+4 more7.17.011
OSV records
GHSA-xm59-rqc7-hhvf
Also known as
PYSEC-2026-1691

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nbconvert@7.14.1
7.17.0

Open the chart page →

12,746
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nbconvert@6.0.7
7.17.0

Open the chart page →

52,919
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
nbconvert@7.14.1
7.17.0

Open the chart page →

14,094
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
nbconvert@5.3.1
7.17.0

Open the chart page →

36,094
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
nbconvert@6.1.0
7.17.0

Open the chart page →

5,305
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
nbconvert@5.3.1
7.17.0

Open the chart page →

29,901
distributed-tensorflowcloudnativeapp0.1.11 of 1See more

distributed-tensorflow cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
cheyang/distributed-tf:1.6.046cc34755493
nbconvert@5.3.1
7.17.0

Open the chart page →

36,094
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
nbconvert@7.16.4
7.17.0

Open the chart page →

16,604
jupyterhubkubeblocksVerified publisher0.1.01 of 7See more

jupyterhub kubeblocks 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
nbconvert@7.7.3
7.17.0

Open the chart page →

7,356
kyso-nbdimekyso1.0.01 of 1See more

kyso-nbdime kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
kyso/kyso-nbdime:latest4aa9d38ee81d
nbconvert@7.2.7
7.17.0

Open the chart page →

2,765
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-53000.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
nbconvert@6.3.0
7.17.0

Open the chart page →

5,321

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aristidetm/basic-notebook:3.6.5469dbc951224
nbconvert@7.16.4
7.17.0
1
cheyang/distributed-tf:1.6.046cc34755493
nbconvert@5.3.1
7.17.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
nbconvert@5.3.1
7.17.0
1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
nbconvert@7.7.3
7.17.0
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
nbconvert@6.0.7
7.17.0
1
kyso/kyso-nbdime:latest4aa9d38ee81d
nbconvert@7.2.7
7.17.0
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
nbconvert@6.3.0
7.17.0
1
pangeo/base-notebook:2024.01.155fbe688a4f80
nbconvert@7.14.1
7.17.0
1
robmarkcole/deepstack-ui:latest410275726459
nbconvert@6.1.0
7.17.0
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
nbconvert@5.3.1
7.17.0
1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
nbconvert@7.14.1
7.17.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.