CVE-2025-32428

CRITICAL

Pypi Jupyter-remote-desktop-proxy < 3.0.1 - Exposure to Wrong Actor

Title source: rule
STIX 2.1

Description

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.

Scores

CVSS v4 9.0
EPSS 0.0016
EPSS Percentile 36.2%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-668
Status published
Products (2)
jupyterhub/jupyter-remote-desktop-proxy >= 3.0.0, < 3.0.1
pypi/jupyter-remote-desktop-proxy 3.0.0 - 3.0.1PyPI
Published Apr 15, 2025
Tracked Since Feb 18, 2026