PT-2026-71310 · Project Jupyter · Jupyterlab
CVE-2026-73415
·
Published
2026-07-22
·
Updated
2026-08-28
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
JupyterLab versions prior to 4.5.10
JupyterLab versions prior to 4.6.2
Description
The ImageViewer component in
packages/imageviewer/src/widget.ts uses URL.createObjectURL for specially crafted SVG images and revokes the blob URL prematurely. This allows the image to maintain an executable same-origin context when viewed through the image viewer and subsequently opened in a new browser tab. This flaw leads to cross-site scripting (XSS), which can be leveraged to execute arbitrary code on the server.Recommendations
Update to version 4.5.10.
Update to version 4.6.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyterlab