jupyterlab
PyPI18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting jupyterlabpage 1 of 1
- CVE-2021-32797HIGHCVSS 7.4EG 7.4fixed in 1.2.21, 2.2.10, 2.3.2, 3.0.17 or 3.1.4, by version range2021-08-09
vulnerable: 0.0.1 ... 3.1.2 (294 versions)
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribu…
- CVE-2024-22420MEDIUMCVSS 6.5EG 6.5fixed in 4.0.112024-01-19
vulnerable: 4.0.0 ... 4.0.9 (11 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab previe…
- CVE-2024-22421HIGHCVSS 7.6EG 7.6fixed in 4.0.11 or 3.6.7, by version range2024-01-19
vulnerable: 0.0.1 ... 4.0.9 (451 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens expo…
- CVE-2024-39700CRITICALCVSS 9.9EG 9.9fixed in 4.3.02024-07-16
vulnerable: 0.0.1 ... 4.3.0rc1 (539 versions)
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors …
- CVE-2024-43805HIGHCVSS 7.6EG 7.6fixed in 3.6.8 or 4.2.5, by version range2024-08-28
vulnerable: 0.0.1 ... 4.2.4 (486 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown…
- CVE-2025-59842MEDIUMCVSS 4.3EG 4.3fixed in 4.4.82025-09-26
vulnerable: 0.0.1 ... 4.4.7 (565 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterL…
- CVE-2026-102830MEDIUMCVSS 6.8EG 6.8fixed in 4.6.4 or 4.5.11, by version range2026-09-29
vulnerable: 3.0.0 ... 4.6.3 (265 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms heade…
- CVE-2026-102831HIGHCVSS 8.1EG 8.1fixed in 4.6.4 or 4.5.11, by version range2026-09-29
vulnerable: 4.5.0 ... 4.6.3 (15 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 …
- CVE-2026-102904MEDIUMCVSS 5.4EG 5.4fixed in 4.6.4 or 4.5.11, by version range2026-09-29
vulnerable: 4.0.0 ... 4.6.3 (110 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHan…
- CVE-2026-40171HIGHCVSS 8.4EG 8.4fixed in 4.5.72026-05-06
vulnerable: 0.0.1 ... 4.5.6 (584 versions)
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting i…
- CVE-2026-42266HIGHCVSS 8.8EG 8.8fixed in 4.5.72026-05-13
vulnerable: 4.0.0 ... 4.5.6 (102 versions)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_ex…
- CVE-2026-42557CRITICALCVSS 9.6EG 9.6fixed in 4.5.72026-05-13
vulnerable: 0.0.1 ... 4.5.6 (584 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args o…
- CVE-2026-67338MEDIUMCVSS 6.1EG 6.1fixed in 4.5.92026-08-01
vulnerable: 0.0.1 ... 4.5.8 (586 versions)
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in pro…
- CVE-2026-73415HIGHCVSS 7.5EG 7.5fixed in 4.6.2 or 4.5.10, by version range2026-08-12
vulnerable: 0.0.1 ... 4.6.1 (589 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjec…
- CVE-2026-73416MEDIUMCVSS 6.1EG 6.1fixed in 4.6.2 or 4.5.10, by version range2026-07-22
vulnerable: 4.5.0 ... 4.6.1 (12 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jupyt…
- CVE-2026-73417HIGHCVSS 8.6EG 8.6fixed in 4.6.2 or 4.5.10, by version range2026-07-22
vulnerable: 3.3.0 ... 4.6.1 (189 versions)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an over…
- CVE-2026-73626HIGHCVSS 7.5EG 7.5fixed in 4.6.2 or 4.5.10, by version range2026-08-13
vulnerable: 0.0.1 ... 4.5.9 (587 versions)
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blockl…
- CVE-2026-73627MEDIUMCVSS 6.0EG 6.0fixed in 4.6.2 or 4.5.10, by version range2026-08-13
vulnerable: 4.1.0 ... 4.5.9 (82 versions)
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules b…
Check whether jupyterlab is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for jupyterlab CVEs against the assets you own.
Book a Demo →