All vulnerabilities CVE-2026-77359 · GHSA-9x8x-crjq-g64h Browser DNS rebinding can hijack the Jupyter backend through management routes criticalCWE-350 Vendor datalayer Package jupyter-mcp-server pip Affected <= 1.0.2 Disclosed 2026-07-12 Credit Avishai Gonen dns-rebindingmcpjupyter Published advisory Technical writeup