๐Ÿ” CVE Alert

CVE-2026-67338

MEDIUM 6.1

JupyterLab before 4.5.9 Stored XSS via Extension Manager

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

CWE CWE-84
Vendor jupyterlab
Product jupyterlab
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for jupyterlab jupyterlab

Be the first to know when new medium vulnerabilities affecting jupyterlab jupyterlab are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

jupyterlab / jupyterlab
0 < 4.5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4 github.com: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 github.com: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 vulncheck.com: https://www.vulncheck.com/advisories/jupyterlab-before-stored-xss-via-extension-manager

Credits

๐Ÿ” krassowski Yann-P