PatchSiren

jupyterlab CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM jupyterlab CVE published 2026-08-01

CVE-2026-67338

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager. The vulnerability fails to validate URI protocols in package metadata URLs, allowing attackers to publish malicious PyPI packages with javascript: URLs in project metadata. These URLs can execute arbitrary JavaScript in the JupyterLab origin when users click the extension name. This vulnerability can be [truncated]

CRITICAL jupyterlab CVE published 2026-07-08

CVE-2026-54527

The JupyterLab Git extension for JupyterLab, from version 0.30.0b3 before 0.54.0, contains a vulnerability. The PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history. This allows a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab.

HIGH jupyterlab CVE published 2026-05-13

CVE-2026-42266

CVE-2026-42266 affects JupyterLab versions 4.0.0 through 4.5.6. The issue is an enforcement failure in the PyPI Extension Manager allow-list: allowed_extensions_uris is not correctly enforced, and the Extension Manager was not contained to packages listed on the default PyPI index. The issue is fixed in JupyterLab 4.5.7. Based on the published CVSS vector, this is a high-severity issue with network attack [truncated]