CVE-2025-23205 - CVE House
Back to Database
Status published Medium CVE-2025-23205

`frame-ancestors: self` grants all users access to formgrader in nbgrader

Vulnerability Description

nbgrader is a system for assigning and grading notebooks. Enabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomains = False`. #1915 disables a protection which would allow user Alice to craft a page embedding formgrader in an IFrame. If Bob visits that page, his credentials will be sent and the formgrader page loaded. Because Alice's page is on the same Origin as the formgrader iframe, Javasript on Alice's page has _full access_ to the contents of the page served by formgrader using Bob's credentials. This issue has been addressed in release 0.9.5 and all users are advised to upgrade. Users unable to upgrade may disable `frame-ancestors: self`, or enable per-user and per-service subdomains with `JupyterHub.enable_subdomains = True` (then even if embedding in an IFrame is allowed, the host page does not have access to the contents of the frame).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-23205

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

nbgrader
Vulnerable Versions:
= 0.9.4

Timeline

Official Publish: January 17th, 2025
Last Modified: February 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)