PT-2026-67362 · Pypi · Jupyterlab
Published
2026-07-22
·
Updated
2026-07-22
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to
/lab/api/plugins.Impact
Users could workaround the plugin manager lock rules via direct API access for either:
- child plugins of extensions covering multiple plugins
- when "lock all" was issued by the administrator
The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms.
Patches
Users of applications that depend on JupyterLab, such as Notebook v7+, should update
jupyterlab package too.Workarounds
Manually lock all plugins that should be locked. The core plugin identifiers can be found in [the documentation](https://jupyterlab.readthedocs.io/en/latest/extension/extension points.html#core-plugins) and identifiers for all installed extensions are listed in the Plugin Manager.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterlab