PT-2026-102922 · Project Jupyter · Jupyterlab
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JupyterLab versions 4.0.0 through 4.5.10
JupyterLab versions 4.6.0 through 4.6.3
Description
In the PyPI Extension Manager, the
ExtensionHandler.post function validates extension names during installation but fails to reject option-like values during uninstallation. These values are passed directly to PyPIExtensionManager.uninstall and the python -m pip uninstall command. An authenticated user with access to the extension API can provide a pip requirements option to force the server to read a local file or fetch an internal URL, where reflected parse errors may reveal the first unparsable line or response content. Additionally, a pip log option can be used to create or corrupt a specific file path with pip-generated log text. This issue requires the PyPI Extension Manager to be enabled and the user to have extension API access.Recommendations
Update JupyterLab to version 4.5.11 or 4.6.4.
Exploit
Fix
SSRF
Generation of Error Message Containing Sensitive Information
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterlab