PT-2026-71455 · Project Jupyter · Jupyterlab

·

CVE-2026-73627

·

Published

2026-08-13

·

Updated

2026-08-28

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions JupyterLab versions 4.1.0 through 4.5.9 JupyterLab versions 4.6.0 through 4.6.1
Description A plugin manager lock-rule enforcement bypass exists where server-side gaps allow an authenticated user to circumvent administrator lock rules. By making direct requests to the '/lab/api/plugins' endpoint, a user can enable or disable locked plugins, including child plugins of multi-plugin extensions and those locked via the 'lock all' mechanism. This may lead to compromised data integrity and the bypass of hardening restrictions, such as download or upload limits, established through locked plugins.
Recommendations Update versions 4.1.0 through 4.5.9 to version 4.5.10. Update versions 4.6.0 through 4.6.1 to version 4.6.2.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73627
OPENSUSE-SU-2026:11634-1

Affected Products

Jupyterlab