PT-2026-102922 · Project Jupyter · Jupyterlab

·

CVE-2026-102904

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JupyterLab versions 4.0.0 through 4.5.10 JupyterLab versions 4.6.0 through 4.6.3
Description In the PyPI Extension Manager, the ExtensionHandler.post function validates extension names during installation but fails to reject option-like values during uninstallation. These values are passed directly to PyPIExtensionManager.uninstall and the python -m pip uninstall command. An authenticated user with access to the extension API can provide a pip requirements option to force the server to read a local file or fetch an internal URL, where reflected parse errors may reveal the first unparsable line or response content. Additionally, a pip log option can be used to create or corrupt a specific file path with pip-generated log text. This issue requires the PyPI Extension Manager to be enabled and the user to have extension API access.
Recommendations Update JupyterLab to version 4.5.11 or 4.6.4.

Exploit

Fix

SSRF

Generation of Error Message Containing Sensitive Information

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102904
GHSA-3325-V43H-43RV

Affected Products

Jupyterlab