notebook
Jupyter Interactive Notebook
Activity
- Latest release
- 1mo ago
- Total releases
- 212
- Cadence
- ~7 days
- Last 12 months
- 26
Reach
- Stars
- 13.3k
Details
- License
- custom
- First release
- Jul 30, 2015
| Version | Released | |
|---|---|---|
7.6.2
patch
| ||
7.6.1
patch
| ||
7.7.0a1
pre
| ||
7.7.0a0
pre
| ||
7.6.0
minor
| ||
7.6.0rc1
pre
| ||
7.6.0rc0
pre
| ||
7.5.7
patch
| ||
7.6.0b1
pre
| ||
7.6.0b0
pre
| ||
7.5.6
patch
| ||
7.6.0a5
pre
| ||
7.6.0a4
pre
| ||
7.5.5
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.4
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.6.0a3
pre
| ||
7.5.3
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.6.0a2
pre
| ||
7.6.0a1
pre
| ||
7.5.2
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.6.0a0
pre
| ||
7.5.1
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0
minor
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0rc1
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0rc0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0b1
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0b0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.7
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.6
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0a3
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0a2
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0a1
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.5
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.4
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.3
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.5.0a0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.2
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.1
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0
minor
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0rc0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0b3
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0b2
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.3.3
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0b1
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0b0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0a3
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0a2
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0a1
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.4.0a0
pre
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
7.3.2
patch
2 CVEs
CVE-2026-42557
PYSEC-2026-2681
BIT-jupyter-base-notebook-2026-42557
BIT-jupyter-notebook-2026-42557
BIT-jupyterlab-2026-42557
GHSA-mqcg-5x36-vfcg
PYSEC-2026-2537
Jul 13, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Critical
Network
Low
None
JupyterLab's HTML sanitizer allowlists ImpactAn attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by the victim. The button can be rendered inside the output area and be visually indistinguishable from a legitimate widget. No kernel needs to start; the HTML output is stored in the notebook file and displayed immediately on open. Single-click impactAn attacker convincing the victim to click on a single button or link can:
The arbitrary code execution will be immediately visible to the user; and can be halted by the timely user intervention. The deletion of files can be silent and go unnoticed for some time. Multi-click attacksAn attacker who convinces the victim to click on multiple buttons in specific order and to grant access to clipboard (or in scenarios where the user already granted keyboard access) can obtain full access to the terminal and execute arbitrary commands in the environment with access scope that might exceed that of available kernels. Only users of Chromium-based browsers are susceptible to this expanded variant of the attack. The execution of commands in the terminal would be immediately visible to the user. Impact of third-party extensionsThe impact described above assumes a plain JupyterLab/Notebook installation. In environments with frontend extensions that contribute additional commands the attack surface is increased by the functionality covered by these commands. PatchesJupyterLab 4.5.7 WorkaroundsNo workarounds are available for end-users. Downstream applications inheriting from HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40171
PYSEC-2026-2682
BIT-jupyter-base-notebook-2026-40171
BIT-jupyter-notebook-2026-40171
BIT-jupyterlab-2026-40171
GHSA-rch3-82jr-f9w9
PYSEC-2026-2538
Jul 13, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Critical
Network
Low
High
ImpactA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction). The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
PatchesJupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability. WorkaroundsThe help extension can be disabled via CLI:
HardeningThe patched versions include a toggle to disable the command linker functionality altogether, for example via
Resources
AcknowledgmentsReported by Daniel Teixeira - NVIDIA AI Red Team Affected versions
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.1.0
7.1.0a0
7.1.0a1
+ 57 more Show less
7.1.0a2
7.1.0b0
7.1.0rc0
7.1.0rc1
7.1.1
7.1.2
7.1.3
7.2.0
7.2.0a0
7.2.0b0
7.2.0b1
7.2.0rc0
7.2.0rc1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.0a0
7.3.0a1
7.3.0b0
7.3.0b1
7.3.0b2
7.3.0rc0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.0a0
7.4.0a1
7.4.0a2
7.4.0a3
7.4.0b0
7.4.0b1
7.4.0b2
7.4.0b3
7.4.0rc0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
7.4.6
7.4.7
7.5.0
7.5.0a0
7.5.0a1
7.5.0a2
7.5.0a3
7.5.0b0
7.5.0b1
7.5.0rc0
7.5.0rc1
7.5.1
7.5.2
7.5.3
7.5.4
7.5.5
Fixed in
7.5.6
References
Updated Jul 13, 2026 · Source: OSV.dev |