Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

jupyterlab — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting jupyterlab. AI-powered Chinese analysis, POCs, and references for each vulnerability.

JupyterLab serves as an interactive development environment for data science and computational research, enabling code execution, visualization, and collaboration. Historically, it has been susceptible to remote code execution (RCE) through crafted notebook files, cross-site scripting (XSS) via malicious inputs, and privilege escalation in multi-user deployments. Security incidents often stem from improper input validation and insufficient sandboxing of executed code. With seven CVEs documented, common vulnerabilities include path traversal attacks and authentication bypasses. While JupyterLab remains widely adopted, users must implement strict access controls and input sanitization to mitigate risks, particularly in shared or internet-facing deployments where untrusted notebooks pose significant threats.

High2026-08-14
Cross-site scripting (XSS) in JupyterLab via crafted settings file (`overrides.json`) · Advisory · jupyterlab/jupyterlab
MediumCVE-2026-734282026-08-14
PyPI extension blocklist package-name canonicalization bypass · Advisory · jupyterlab/jupyterlab · GitHub
High2026-08-13
Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`) · Adviso
MediumGHSA-h5v5-8746-g7mm2026-08-13
JupyterLab PluginManager lock-rule enforcement bypass · Advisory · jupyterlab/jupyterlab · GitHub
High2026-08-13
Security patches by krassowski · Pull Request #19184 · jupyterlab/jupyterlab · GitHub
HighCVE-2026-734152026-08-13
Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab · Advisory · jupyterlab/jupyterlab
Medium2026-08-13
Backport of security patches to `4.5.x` branch (#19186) · jupyterlab/jupyterlab@be9303f · GitHub
HighGHSA-gw54-g6gp-pc4c2026-08-13
Backport of security patches to `4.6.x` branch by krassowski · Pull Request #19185 · jupyterlab/jupyterlab · GitHub
HighGHSA-gx64-g63p-nc3c2026-08-13
Release v4.6.2 · jupyterlab/jupyterlab · GitHub
Unknown2026-08-13
Release v4.5.10 · jupyterlab/jupyterlab · GitHub
Medium2026-08-01
Fix XSS in extension manager's `homepage_url` (#19003) · jupyterlab/jupyterlab@4e61e07 · GitHub
MediumGHSA-vmhf-c436-hxj42026-08-01
Stored XSS in extension manager through package metadata unsanitized URI protocol · Advisory · jupyterlab/jupyterlab · G
Unknown2026-08-01
Forbid relative URLs in extensionmanager (#19013) · jupyterlab/jupyterlab@d5d961f · GitHub
High2026-07-09
Merge commit from fork · jupyterlab/jupyterlab-git@4600352 · GitHub
Medium2026-07-09
Merge commit from fork · jupyterlab/jupyterlab-git@c6d37b8 · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with jupyterlab. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.