๐Ÿ” CVE Alert

CVE-2026-73627

UNKNOWN 0.0

JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked โ€” including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.

CWE CWE-602
Vendor jupyterlab
Product jupyterlab
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for jupyterlab jupyterlab

Be the first to know when new unknown vulnerabilities affecting jupyterlab jupyterlab are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

jupyterlab / jupyterlab
All versions affected
jupyterlab / jupyterlab
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm vulncheck.com: https://www.vulncheck.com/advisories/jupyterlab-plugin-manager-lock-rule-enforcement-bypass

Credits

๐Ÿ” rexpository MUFFANUJ krassowski