CVE-2025-32428
CRITICALPypi Jupyter-remote-desktop-proxy < 3.0.1 - Exposure to Wrong Actor
Title source: ruleDescription
Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.
Scores
CVSS v4
9.0
EPSS
0.0016
EPSS Percentile
36.2%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-668
Status
published
Products (2)
jupyterhub/jupyter-remote-desktop-proxy
>= 3.0.0, < 3.0.1
pypi/jupyter-remote-desktop-proxy
3.0.0 - 3.0.1PyPI
Published
Apr 15, 2025
Tracked Since
Feb 18, 2026