PT-2026-71310 · Project Jupyter · Jupyterlab

CVE-2026-73415

·

Published

2026-07-22

·

Updated

2026-08-28

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions JupyterLab versions prior to 4.5.10 JupyterLab versions prior to 4.6.2
Description The ImageViewer component in packages/imageviewer/src/widget.ts uses URL.createObjectURL for specially crafted SVG images and revokes the blob URL prematurely. This allows the image to maintain an executable same-origin context when viewed through the image viewer and subsequently opened in a new browser tab. This flaw leads to cross-site scripting (XSS), which can be leveraged to execute arbitrary code on the server.
Recommendations Update to version 4.5.10. Update to version 4.6.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JUPYTERLAB-2026-73415
CVE-2026-73415
GHSA-GX64-GJ6P-PC4C
OPENSUSE-SU-2026:11634-1
PYSEC-2026-3671

Affected Products

Jupyterlab