jupyterlab
JupyterLab computational environment.
Activity
- Latest release
- 1mo ago
- Total releases
- 603
- Cadence
- ~6 days
- Last 12 months
- 31
Reach
- Stars
- 15.3k
Details
- License
- custom
- First release
- Jun 04, 2016
| Version | Released | |
|---|---|---|
4.6.3
patch
| ||
4.7.0a1
pre
| ||
4.5.10
patch
| ||
4.6.2
patch
| ||
4.6.1
patch
5 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.7.0a0
pre
| ||
4.6.0
minor
5 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.5.9
patch
5 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.6.0rc1
pre
| ||
4.6.0rc0
pre
| ||
4.5.8
patch
6 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.6.0b1
pre
| ||
4.6.0b0
pre
| ||
4.5.7
patch
6 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
4.6.0a5
pre
| ||
4.5.6
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.6.0a4
pre
| ||
4.5.5
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.6.0a3
pre
| ||
4.5.4
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.3
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.6.0a2
pre
| ||
4.6.0a1
pre
| ||
4.5.2
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.6.0a0
pre
| ||
4.5.1
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0
minor
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73416
PYSEC-2026-3670
BIT-jupyterlab-2026-73416
GHSA-89vp-jrxv-24w8
Aug 19, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
High
Network
Low
Low
None
JupyterLab's PyPI extension manager enforces This has security implications only for deployments that combine all of the following:
ImpactThe vulnerability lets an authenticated user install a package the operator specifically intended to block, defeating the allowlist/blocklist control. Because extensions in principle allow for arbitrary code execution, this vulnerability enables untrusted users to impact the integrity and availability of the jupyter-server instance that was provisioned to them. The user already has access to their own single-user server's data, so installing an extension grants no new read access. In particular, the integrity of data can be impacted, and any hardening or restrictions on permitted user actions (download/upload limits) within the single-user server can be circumvented. Availability impact on a JupyterHub deployment is limited: while a user can be expected to exhaust their own kernel pod's resources, this vulnerability makes it easier to also exhaust the single-user server resources or generate more requests to shared resources; where limits are absent, resource exhaustion could potentially degrade the wider deployment. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that do not have a custom allow/block list configured. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0rc1
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0rc0
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.10
patch
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0b1
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0b0
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.9
patch
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.8
patch
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0a4
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.7
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0a3
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.6
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0a2
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.5
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.4
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.3.8
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0a1
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.3
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.5.0a0
pre
8 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.2
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.3.7
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.1
patch
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.0
minor
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev | ||
4.4.0rc1
pre
9 CVEs
CVE-2026-73417
PYSEC-2026-3672
BIT-jupyterlab-2026-73417
GHSA-pppj-hq3g-57pj
Aug 19, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Critical
Network
Low
None
JupyterLab 4.5+ allows notebook settings to be shared and applied through an Certain notebook display settings were not properly validated before being applied. As a result, a crafted settings file could contain hidden instructions that run as code inside JupyterLab when imported, instead of only changing a display preference. Because importing a settings file appears harmless, a user could import a file shared by another party without realizing it could do more. On multi-tenant file systems without proper permission control, another user could plant a malicious
ImpactWhen a malicious settings file is applied, the embedded code runs with the same access as the affected user. This could allow an attacker to read or modify that user's notebooks and files, and to run code on the user's behalf through the notebook server, including on any connected kernel. User Interaction vs Privileges RequiredWrite access to a loaded settings locationIf an attacker can write to a directory JupyterLab loads settings from (e.g. on shared or multi-tenant file system), they could place a crafted User-imported settings fileA user can import a crafted PatchesJupyterLab 4.6.2 and 4.5.10 were patched. WorkaroundsNone Hardening
Affected versions
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
+ 177 more Show less
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
CVE-2026-73415
PYSEC-2026-3671
BIT-jupyterlab-2026-73415
GHSA-gx64-gj6p-pc4c
Aug 19, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Critical
Network
High
None
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ImpactThis vulnerability allows for arbitrary code execution. PatchesJupyterLab WorkaroundsDisable the image viewer plugin:
Confirm with:
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 577 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
4.6.0
4.6.1
Fixed in
4.5.10
4.6.2
References
Updated Aug 19, 2026 · Source: OSV.dev
GHSA-h5v5-8746-g7mm
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Medium
Network
Low
Low
None
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to ImpactUsers could workaround the plugin manager lock rules via direct API access for either:
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsManually lock all plugins that should be locked. The core plugin identifiers can be found in the documentation and identifiers for all installed extensions are listed in the Plugin Manager. Affected versions
4.6.0
4.6.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
+ 72 more Show less
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-73626
GHSA-whvh-wf3x-g77j
Jul 22, 2026
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
0.0
/ 10
None
Network
Low
Low
None
Unchanged
None
None
None
The extension allowlist/blocklist check inside This has security implications only for deployments that combine all of the following:
ImpactLow. No exposure for stock JupyterLab: the HTTP API and Extension Manager UI enforce the listing through a separate, correctly awaited check. The gap affected only custom extensions or downstream integrations that called the public PatchesJupyterLab Users of applications that depend on JupyterLab, such as Notebook v7+, should update WorkaroundsNo action is required for deployments that only expose extension management through the JupyterLab HTTP API / Extension Manager UI, as that path was already enforcing the listing via the handler's own check. Deployments wanting to disable programmatic extension installation entirely can switch to the read-only extension manager:
or the following traitlet:
You can confirm that the read-only manager is in use from GUI: Affected versions
4.6.0
4.6.1
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
+ 577 more Show less
0.0.9
0.1.1
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9
Fixed in
4.5.10
4.6.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42557
PYSEC-2026-2537
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2681
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2538
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2682
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 572 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-59842
PYSEC-2026-1482
BIT-jupyterlab-2025-59842
GHSA-vvfj-2jqx-52jm
Jul 07, 2026
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Medium
Network
High
None
Links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if:
For consistency with handling on other links, new versions of JupyterLab will enforce ImpactSince the official LaTeX typesetter extensions for JupyterLab: PatchesJupyterLab 4.4.8 WorkaroundsNo workarounds are necessary. ReferencesNone Affected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 553 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
Fixed in
4.4.8
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-67338
GHSA-vmhf-c436-hxj4
Jun 19, 2026
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Medium
Network
Low
None
A malicious PyPI package can place a DetailsOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the
ImpactAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin. Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results. PatchesAffected versions
0.0.1
0.0.10
0.0.13
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.1
+ 574 more Show less
0.1.2
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.12.1
0.13.0
0.13.1
0.13.2
0.14.0
0.15.0
0.15.1
0.16.0
0.16.2
0.17.0
0.17.1
0.17.2
0.17.4
0.17.5
0.18.0
0.18.0.dev1
0.18.1
0.19.0
0.2.0
0.20.0
0.20.0rc1
0.20.1
0.20.2
0.20.3
0.20.4
0.21.0
0.21.0rc1
0.21.0rc2
0.21.0rc3
0.21.0rc4
0.21.0rc5
0.22.0
0.22.0rc0
0.22.1
0.23.0
0.23.0rc0
0.23.0rc1
0.23.1
0.23.2
0.24.0
0.24.0rc0
0.24.0rc1
0.24.0rc2
0.24.1
0.25.0
0.25.0rc0
0.25.0rc1
0.25.1
0.25.2
0.25.2rc0
0.26.0
0.26.0rc0
0.26.0rc1
0.26.1
0.26.2
0.26.3
0.26.4
0.26.5
0.27.0
0.27.0rc0
0.27.0rc1
0.27.0rc2
0.27.0rc3
0.27.0rc4
0.27.0rc5
0.27.1
0.27.2
0.28.0
0.28.0rc0
0.28.0rc1
0.28.0rc2
0.28.0rc3
0.28.1
0.28.10
0.28.11
0.28.12
0.28.13
0.28.14
0.28.15
0.28.2
0.28.3
0.28.4
0.28.5
0.28.6
0.28.7
0.28.8
0.29.0
0.29.0rc0
0.29.1
0.29.2
0.3.0
0.30.0
0.30.0rc0
0.30.0rc1
0.30.1
0.30.2
0.30.3
0.30.4
0.30.5
0.30.6
0.31.0
0.31.0rc0
0.31.0rc1
0.31.0rc2
0.31.1
0.31.10
0.31.11
0.31.12
0.31.2
0.31.3
0.31.4
0.31.5
0.31.6
0.31.7
0.31.8
0.31.9
0.32.0
0.32.0rc0
0.32.0rc1
0.32.1
0.33.0
0.33.0rc0
0.33.0rc1
0.33.1
0.33.10
0.33.11
0.33.12
0.33.2
0.33.3
0.33.4
0.33.5
0.33.6
0.33.7
0.33.8
0.33.9
0.34.0
0.34.0rc0
0.34.0rc1
0.34.0rc2
0.34.1
0.34.10
0.34.11
0.34.12
0.34.2
0.34.3
0.34.4
0.34.5
0.34.6
0.34.7
0.34.8
0.34.9
0.35.0
0.35.0rc0
0.35.0rc1
0.35.0rc2
0.35.1
0.35.2
0.35.3
0.35.4
0.35.5
0.35.6
0.4.0
0.4.1
0.5.0
0.6.0
0.7.0
0.8.0
0.9.0
0.9.1
1.0.0
1.0.0a0
1.0.0a1
1.0.0a10
1.0.0a2
1.0.0a3
1.0.0a4
1.0.0a5
1.0.0a6
1.0.0a7
1.0.0a8
1.0.0a9
1.0.0rc0
1.0.0rc1
1.0.1
1.0.10
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.9
1.1.0
1.1.0a0
1.1.0a1
1.1.0a2
1.1.0rc0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.2.0
1.2.0a0
1.2.0a1
1.2.0a2
1.2.0a3
1.2.0rc0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
2.0.0
2.0.0a0
2.0.0a1
2.0.0a3
2.0.0a4
2.0.0b1
2.0.0b2
2.0.0b3
2.0.0rc0
2.0.0rc1
2.0.0rc2
2.0.1
2.0.1rc0
2.0.2
2.1.0
2.1.0a0
2.1.0b0
2.1.0rc0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.0a0
2.2.0a1
2.2.0rc1
2.2.1
2.2.10
2.2.2
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.0a0
2.3.0a1
2.3.0a2
2.3.0rc0
2.3.1
2.3.2
3.0.0
3.0.0a0
3.0.0a10
3.0.0a11
3.0.0a12
3.0.0a13
3.0.0a14
3.0.0a3
3.0.0a4
3.0.0a5
3.0.0a6
3.0.0a7
3.0.0a8
3.0.0a9
3.0.0b1
3.0.0b2
3.0.0b3
3.0.0b4
3.0.0b6
3.0.0b7
3.0.0b8
3.0.0rc0
3.0.0rc1
3.0.0rc10
3.0.0rc11
3.0.0rc12
3.0.0rc13
3.0.0rc14
3.0.0rc15
3.0.0rc2
3.0.0rc3
3.0.0rc4
3.0.0rc5
3.0.0rc6
3.0.0rc7
3.0.0rc8
3.0.0rc9
3.0.1
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16
3.0.17
3.0.18
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.1.0
3.1.0a0
3.1.0a1
3.1.0a10
3.1.0a11
3.1.0a12
3.1.0a13
3.1.0a2
3.1.0a3
3.1.0a4
3.1.0a5
3.1.0a6
3.1.0a7
3.1.0a8
3.1.0a9
3.1.0b0
3.1.0b1
3.1.0rc1
3.1.0rc2
3.1.1
3.1.10
3.1.11
3.1.12
3.1.13
3.1.14
3.1.16
3.1.17
3.1.18
3.1.19
3.1.2
3.1.4
3.1.6
3.1.7
3.1.8
3.1.9
3.2.0
3.2.0a0
3.2.0a1
3.2.0b0
3.2.0rc0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.0a1
3.3.0a2
3.3.0a3
3.3.0b0
3.3.0rc0
3.3.1
3.3.2
3.3.3
3.3.4
3.4.0
3.4.0a0
3.4.0b0
3.4.0rc0
3.4.1
3.4.2
3.4.3
3.4.4
3.4.5
3.4.6
3.4.7
3.4.8
3.5.0
3.5.0a0
3.5.0b0
3.5.0rc0
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0a0
3.6.0a1
3.6.0a2
3.6.0a3
3.6.0a4
3.6.0a5
3.6.0b0
3.6.0rc0
3.6.0rc1
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
4.0.0
4.0.0a0
4.0.0a1
4.0.0a10
4.0.0a11
4.0.0a12
4.0.0a13
4.0.0a14
4.0.0a15
4.0.0a16
4.0.0a17
4.0.0a18
4.0.0a19
4.0.0a20
4.0.0a21
4.0.0a22
4.0.0a23
4.0.0a24
4.0.0a25
4.0.0a26
4.0.0a27
4.0.0a28
4.0.0a29
4.0.0a3
4.0.0a30
4.0.0a31
4.0.0a32
4.0.0a33
4.0.0a34
4.0.0a35
4.0.0a36
4.0.0a4
4.0.0a6
4.0.0a7
4.0.0a8
4.0.0a9
4.0.0b0
4.0.0b1
4.0.0b2
4.0.0rc0
4.0.0rc1
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
Fixed in
4.5.9
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-42266
PYSEC-2026-164
BIT-jupyterlab-2026-42266
GHSA-37w4-hwhx-4rc4
May 13, 2026
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. Affected versions
4.0.0
4.0.1
4.0.10
4.0.11
4.0.12
4.0.13
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
+ 90 more Show less
4.0.8
4.0.9
4.1.0
4.1.0a1
4.1.0a2
4.1.0a3
4.1.0a4
4.1.0b0
4.1.0b1
4.1.0b2
4.1.0rc0
4.1.0rc1
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.2.0
4.2.0a0
4.2.0a1
4.2.0a2
4.2.0b0
4.2.0b1
4.2.0b2
4.2.0b3
4.2.0rc0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7
4.3.0
4.3.0a0
4.3.0a1
4.3.0a2
4.3.0b0
4.3.0b1
4.3.0b2
4.3.0b3
4.3.0rc0
4.3.0rc1
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.0a0
4.4.0a1
4.4.0a2
4.4.0a3
4.4.0b0
4.4.0b1
4.4.0b2
4.4.0rc0
4.4.0rc1
4.4.1
4.4.10
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.0a0
4.5.0a1
4.5.0a2
4.5.0a3
4.5.0a4
4.5.0b0
4.5.0b1
4.5.0rc0
4.5.0rc1
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
Fixed in
4.5.7
References
Updated May 27, 2026 · Source: OSV.dev |