PT-2026-102815 · Project Jupyter · Jupyterlab+1
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
JupyterLab versions 3.0.0 through 4.5.10
JupyterLab versions 4.6.0 through 4.6.3
JupyterLite Core versions 0.x through 0.8.3
Description
An issue exists where the Plural-Forms header in selected third-party language packs can append JavaScript after a valid plural rule. This occurs because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to the
new Function() function, causing the appended code to execute in the authenticated JupyterLab origin when loading the catalogue and translating a plural string. In environments where Jupyter Server kernels, terminals, and APIs are exposed, this can allow the execution of code to read or modify files and run commands via authenticated server APIs. The impact is more limited in JupyterLite due to fewer exposed server surfaces. The default English locale is not affected.Recommendations
Update JupyterLab to version 4.5.11 or 4.6.4.
Update JupyterLite Core to version 0.8.4.
Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterlab
Jupyterlite-Core