PT-2026-71455 · Project Jupyter · Jupyterlab
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
JupyterLab versions 4.1.0 through 4.5.9
JupyterLab versions 4.6.0 through 4.6.1
Description
A plugin manager lock-rule enforcement bypass exists where server-side gaps allow an authenticated user to circumvent administrator lock rules. By making direct requests to the '/lab/api/plugins' endpoint, a user can enable or disable locked plugins, including child plugins of multi-plugin extensions and those locked via the 'lock all' mechanism. This may lead to compromised data integrity and the bypass of hardening restrictions, such as download or upload limits, established through locked plugins.
Recommendations
Update versions 4.1.0 through 4.5.9 to version 4.5.10.
Update versions 4.6.0 through 4.6.1 to version 4.6.2.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyterlab