PT-2026-80644 · Pypi · Jupyterlab
Published
2026-08-19
·
Updated
2026-08-19
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.
Impact
This vulnerability allows for arbitrary code execution.
Patches
Workarounds
Disable the image viewer plugin:
jupyter labextension disable @jupyterlab/imageviewer-extension:pluginConfirm with:
jupyter labextension listFix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jupyterlab