JupyterLab是JupyterLab基金会的一款Web应用开发框架。 JupyterLab 4.5.0至4.5.10之前版本和4.6.0至4.6.2之前版本存在安全漏洞,该漏洞源于JupyterLab的PyPI扩展管理器在比较请求的安装名称与黑名单条目时,使用的自定义规范化弱于PyPI包名规范化,可能导致经过身份验证的用户绕过黑名单安装被禁止的扩展,破坏完整性限制并影响可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyterlab | jupyterlab | >= 4.5.0, < 4.5.10 |
affected |
>= 4.6.0, < 4.6.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyterlab | jupyterlab | >= 4.5.0, < 4.5.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73417 | 8.6 HIGH | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) |
| CVE-2026-73626 | 7.5 HIGH | JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager |
| CVE-2026-73627 | 6.0 MEDIUM | JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass |
No comments yet