NONE · 0

CVE-2025-32428

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, bu...

Vulnerability Description

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-32428?

CVE-2025-32428 is a documented vulnerability. Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, bu...

How severe is CVE-2025-32428?

CVSS scoring is not yet available for CVE-2025-32428. Check NVD for updates.

Is there a patch for CVE-2025-32428?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.