CVE-2025-32428

CRITICAL

jupyter-remote-desktop-proxy 3.0.0 - Exposure of VNC Server to Wrong Sphere via TigerVNC

Title source: llm
STIX 2.1

Description

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.

Scores

CVSS v4 9.0
EPSS 0.0082
EPSS Percentile 52.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-668
Status published
Products (2)
jupyterhub/jupyter-remote-desktop-proxy >= 3.0.0, < 3.0.1
pypi/jupyter-remote-desktop-proxy 3.0.0 - 3.0.1PyPI
Published Apr 15, 2025
Tracked Since Feb 18, 2026