A critical vulnerability has been identified in the nbconvert tool, specifically affecting Jupyter environments on Windows. When converting a notebook containing SVG output to PDF using jupyter nbconvert --to pdf, the tool may inadvertently execute a malicious inkscape.bat file if present in the working directory, leading to unauthorized code execution. This flaw, tracked as CVE-2025-53000, impacts all versions up to and including 7.16.6, and currently, no official patch is available. The vulnerability is not remotely exploitable but poses a significant risk if an attacker can place a crafted batch file in a directory where a user performs notebook exports.
Security researchers have highlighted the broader risks associated with Jupyter notebook export functionality, emphasizing how threat actors could exploit external notebooks to compromise user workstations. The research underscores the importance of securing Jupyter environments, recommending the use of centralized servers, regular updates, and strict controls over external files processed by Jupyter software. The attack vector leverages the fact that configuration files in Jupyter are valid Python executables, making them particularly susceptible to exploitation if not properly managed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
By mid-December 2025, the nbconvert uncontrolled search path vulnerability had been assigned CVE-2025-53000 and publicly described as affecting Windows systems up to and including version 7.16.6. Public reporting stated that no fix was yet available and advised users to avoid vulnerable PDF conversions or harden their environments.
The vulnerability later assigned CVE-2025-53000 was disclosed to the Jupyter team in June 2025. The issue affects nbconvert on Windows by allowing arbitrary code execution during notebook-to-PDF export when a malicious Inkscape script is present in the working directory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.