JupyterLab jupyterlab是JupyterLab基金会的一款Web应用开发框架。 jupyterlab 4.1.0版本至4.5.9版本和4.6.0版本至4.6.1版本存在处理逻辑错误漏洞,该漏洞源于插件管理器锁定规则执行绕过,两个服务端执行漏洞允许已认证用户通过直接请求 /lab/api/plugins 端点绕过管理员锁定规则,启用或禁用已锁定的插件,包括多插件扩展的子插件及通过“全部锁定”机制锁定的插件,可能导致数据完整性受影响并绕过加固或限制(如下载/上传限制)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyterlab | jupyterlab | 4.6.0≤ 4.6.1 |
affected |
4.1.0≤ 4.5.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyterlab | jupyterlab | 4.6.0 ~ 4.6.1 | - |
|
| jupyterlab | jupyterlab | 4.1.0 ~ 4.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73417 | 8.6 HIGH | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) |
| CVE-2026-73626 | 7.5 HIGH | JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager |
| CVE-2026-73416 | 6.1 MEDIUM | jupyterlab: PyPI extension blocklist package-name canonicalization bypass |
No comments yet