Project Jupyter · Jupyterlab · CVE-2026-73627
**Name of the Vulnerable Software and Affected Versions**
JupyterLab versions 4.1.0 through 4.5.9
JupyterLab versions 4.6.0 through 4.6.1
**Description**
A plugin manager lock-rule enforcement bypass exists where server-side gaps allow an authenticated user to circumvent administrator lock rules. By making direct requests to the '/lab/api/plugins' endpoint, a user can enable or disable locked plugins, including child plugins of multi-plugin extensions and those locked via the 'lock all' mechanism. This may lead to compromised data integrity and the bypass of hardening restrictions, such as download or upload limits, established through locked plugins.
**Recommendations**
Update versions 4.1.0 through 4.5.9 to version 4.5.10.
Update versions 4.6.0 through 4.6.1 to version 4.6.2.