PT-2026-80644 · Pypi · Jupyterlab

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

7.5

High

VectorAV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

Impact

This vulnerability allows for arbitrary code execution.

Patches

JupyterLab v4.6.2 and v4.5.10 contain the patch.

Workarounds

Disable the image viewer plugin:
jupyter labextension disable @jupyterlab/imageviewer-extension:plugin
Confirm with:
jupyter labextension list

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-3671

Affected Products

Jupyterlab