We’ve just released JupyterHub 5.5.1, fixing two security vulnerabilities, neither of which affect default configurations:
- GHSA-c4gm-pwx9-9w8j (CVE pending) high-level vulnerability in user-initiated sharing (no effect on deployments without user-initiated sharing)
- GHSA-69wv-m5fw-2fhp (CVE pending) low-level vulnerability in enforcing partial admin-level restrictions (no effect unless you have filtered admin roles:
admin:users!group=...oradmin:groups!group=...)
JupyterHub 5.5.1 is available in the jupyterhub helm chart version 4.4.1, and on PyPI and conda-forge.
Vulnerability details are published 7 days after the patched release (August 17).