๐Ÿ” CVE Alert

CVE-2026-102904

MEDIUM 5.4

JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.

CWE CWE-88 CWE-209 CWE-918
Vendor jupyterlab
Product jupyterlab
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for jupyterlab jupyterlab

Be the first to know when new medium vulnerabilities affecting jupyterlab jupyterlab are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

jupyterlab / jupyterlab
>= 4.0.0, < 4.5.11 >= 4.6.0, < 4.6.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv github.com: https://github.com/jupyterlab/jupyterlab/commit/a274a8276b9185d03efd4c3c20713d3137ac49e6 github.com: https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f github.com: https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11 github.com: https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4