PatchSiren

jupyterlab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH jupyterlab CVE published 2026-08-13

CVE-2026-73417

A vulnerability in JupyterLab allows for code execution through a malicious overrides.json file. This issue is fixed in versions 4.5.10 and 4.6.2. The vulnerability is caused by improper validation of sideBySideLeftMarginOverride and sideBySideRightMarginOverride settings in the tracker.json and index.ts files. A user can import the malicious file, or an attacker with access to a shared settings location [truncated]

HIGH jupyterlab CVE published 2026-08-13

CVE-2026-73626

The CVE-2026-73626 vulnerability affects JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9. It is caused by a missing 'await' in PyPIExtensionManager.install(), leading to an allowlist/blocklist enforcement gap. This issue allows for potential code execution via direct calls to install() with a package name influenced by untrusted input. JupyterLab users and administrators should assess their deployments fo [truncated]

HIGH jupyterlab CVE published 2026-08-12

CVE-2026-73415

A cross-site scripting vulnerability exists in JupyterLab's ImageViewer, allowing arbitrary code execution on the JupyterLab server when a specially crafted SVG image is opened and then opened in a new browser tab. This issue arises from the ImageViewer's use of URL.createObjectURL for a specially crafted SVG image and revoking the blob URL too early, which can lead to malicious code execution in the Jupy [truncated]

MEDIUM jupyterlab CVE published 2026-08-01

CVE-2026-67338

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager. The vulnerability fails to validate URI protocols in package metadata URLs, allowing attackers to publish malicious PyPI packages with javascript: URLs in project metadata. These URLs can execute arbitrary JavaScript in the JupyterLab origin when users click the extension name. This vulnerability can be [truncated]

CRITICAL jupyterlab CVE published 2026-07-08

CVE-2026-54527

The JupyterLab Git extension for JupyterLab, from version 0.30.0b3 before 0.54.0, contains a vulnerability. The PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history. This allows a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab.

HIGH jupyterlab CVE published 2026-05-13

CVE-2026-42266

CVE-2026-42266 affects JupyterLab versions 4.0.0 through 4.5.6. The issue is an enforcement failure in the PyPI Extension Manager allow-list: allowed_extensions_uris is not correctly enforced, and the Extension Manager was not contained to packages listed on the default PyPI index. The issue is fixed in JupyterLab 4.5.7. Based on the published CVSS vector, this is a high-severity issue with network attack [truncated]