PT-2026-67318 · Project Jupyter · Jupyterlab
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
JupyterLab versions prior to 4.5.9
Description
A stored cross-site scripting issue exists in the Extension Manager due to a failure to validate URI protocols in package metadata URLs. An attacker can publish a malicious PyPI package containing a
javascript: URL within the [project.urls] metadata. When a user clicks the extension name in the Extension Manager, the application renders the homepage url without validation, leading to the execution of arbitrary JavaScript in the JupyterLab origin.Recommendations
Update JupyterLab to version 4.5.9 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyterlab