All vulnerabilities CVE-2026-77318 · GHSA-24pw-rf5p-mgp7 Unauthenticated management routes can hijack the Jupyter backend highCWE-306 Vendor datalayer Package jupyter-mcp-server pip Affected <= 1.0.2 Disclosed 2026-07-11 Credit Avishai Gonen auth-bypassmcpjupyter Published advisory Technical writeup