PT-2026-102815 · Project Jupyter · Jupyterlab+1

·

CVE-2026-102830

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions JupyterLab versions 3.0.0 through 4.5.10 JupyterLab versions 4.6.0 through 4.6.3 JupyterLite Core versions 0.x through 0.8.3
Description An issue exists where the Plural-Forms header in selected third-party language packs can append JavaScript after a valid plural rule. This occurs because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to the new Function() function, causing the appended code to execute in the authenticated JupyterLab origin when loading the catalogue and translating a plural string. In environments where Jupyter Server kernels, terminals, and APIs are exposed, this can allow the execution of code to read or modify files and run commands via authenticated server APIs. The impact is more limited in JupyterLite due to fewer exposed server surfaces. The default English locale is not affected.
Recommendations Update JupyterLab to version 4.5.11 or 4.6.4. Update JupyterLite Core to version 0.8.4.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102830
GHSA-3JQQ-PW4J-PQCJ
OPENSUSE-SU-2026:11945-1
PYSEC-2026-4056
PYSEC-2026-4059

Affected Products

Jupyterlab
Jupyterlite-Core