CVE-2026-67338
MEDIUM
5,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: passive
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: changed
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.
84
Improper Neutralization of Encoded URI Schemes in a Web Page
DraftCommon Consequences
Security Scopes Affected:
Integrity
Potential Impacts:
Unexpected State
Applicable Platforms
Technologies:
Web Based, Web Server
https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b038…
https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3…
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
https://www.vulncheck.com/advisories/jupyterlab-before-stored-xss-via-extension…