{"id":"CVE-2026-73415","title":"jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture","summary":"jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-79","CWE-911"],"vendor":"Red Hat","product":"Red Hat OpenShift AI 2.25","affected":["migration_toolkit_for_applications 8","openshift_ai_rhoai","openshift_ai 2.25"],"patched":["openshift_ai 2.25"],"published":"2026-08-12","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:58:37.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73415","references":[{"url":"https://github.com/jupyterlab/jupyterlab/commit/9365f020baec5221deaf11535ed554c06637c999","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19184","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19185","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19186","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.7.0a1","label":"security-advisories@github.com"},{"url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73415.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-73415"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2514936"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-73415"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73415"},{"url":"https://access.redhat.com/errata/RHSA-2026:65126"},{"url":"https://github.com/jupyterlab/jupyterlab"}],"tags":["nvd","csaf","vex","red-hat","osv","pip"],"epss":0.00574,"epssPercentile":0.45885,"aliases":["GHSA-gx64-gj6p-pc4c","BIT-jupyterlab-2026-73415","PYSEC-2026-3671"],"ecosystem":"pip","cvssSource":"vendor","ingestedAt":"2026-08-13T19:18:20.651Z","slug":"CVE-2026-73415","body":"## Overview\n\njupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73415)\n\nAffected packages:\n\n- `jupyterlab >= 4.6.0, < 4.6.2`\n- `jupyterlab < 4.5.10`\n\nPatched in:\n\n- `jupyterlab 4.6.2`\n- `jupyterlab 4.5.10`\n\nSource: https://osv.dev/vulnerability/GHSA-gx64-gj6p-pc4c\n\n## Vendor advisories\n\n- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)\n- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 8, Red Hat OpenShift AI (RHOAI) · no fix planned: Migration Toolkit for Applications 8, Red Hat OpenShift AI (RHOAI) · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-73415.json)","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201897,"id":"CVE-2026-73415","ts":1789399978655,"field":"cvss","old":null,"new":"8"},{"seq":200627,"id":"CVE-2026-73415","ts":1789397538919,"field":"cvss","old":"8","new":null},{"seq":199341,"id":"CVE-2026-73415","ts":1789395457852,"field":"cvss","old":null,"new":"8"},{"seq":198586,"id":"CVE-2026-73415","ts":1789392137444,"field":"cvss","old":"8","new":null},{"seq":198541,"id":"CVE-2026-73415","ts":1789392065169,"field":"cvss","old":null,"new":"8"},{"seq":196332,"id":"CVE-2026-73415","ts":1789383704124,"field":"cvss","old":"8","new":null},{"seq":195261,"id":"CVE-2026-73415","ts":1789380543417,"field":"cvss","old":null,"new":"8"},{"seq":194048,"id":"CVE-2026-73415","ts":1789378650453,"field":"cvss","old":"8","new":null},{"seq":192835,"id":"CVE-2026-73415","ts":1789376480741,"field":"cvss","old":null,"new":"8"},{"seq":191622,"id":"CVE-2026-73415","ts":1789373557263,"field":"cvss","old":"8","new":null},{"seq":190407,"id":"CVE-2026-73415","ts":1789369421108,"field":"cvss","old":null,"new":"8"},{"seq":189194,"id":"CVE-2026-73415","ts":1789368348845,"field":"cvss","old":"8","new":null},{"seq":187977,"id":"CVE-2026-73415","ts":1789365203877,"field":"cvss","old":null,"new":"8"},{"seq":186764,"id":"CVE-2026-73415","ts":1789363413409,"field":"cvss","old":"8","new":null},{"seq":185550,"id":"CVE-2026-73415","ts":1789361185163,"field":"cvss","old":null,"new":"8"},{"seq":184337,"id":"CVE-2026-73415","ts":1789358276544,"field":"cvss","old":"8","new":null},{"seq":182588,"id":"CVE-2026-73415","ts":1789354278348,"field":"cvss","old":null,"new":"8"},{"seq":181381,"id":"CVE-2026-73415","ts":1789353249559,"field":"cvss","old":"8","new":null},{"seq":180174,"id":"CVE-2026-73415","ts":1789350231586,"field":"cvss","old":null,"new":"8"},{"seq":178967,"id":"CVE-2026-73415","ts":1789348225787,"field":"cvss","old":"8","new":null},{"seq":177760,"id":"CVE-2026-73415","ts":1789346346092,"field":"cvss","old":null,"new":"8"},{"seq":176553,"id":"CVE-2026-73415","ts":1789343132071,"field":"cvss","old":"8","new":null},{"seq":174670,"id":"CVE-2026-73415","ts":1789334843100,"field":"cvss","old":null,"new":"8"},{"seq":173465,"id":"CVE-2026-73415","ts":1789333624920,"field":"cvss","old":"8","new":null},{"seq":172279,"id":"CVE-2026-73415","ts":1789331069905,"field":"cvss","old":null,"new":"8"},{"seq":171093,"id":"CVE-2026-73415","ts":1789328715912,"field":"cvss","old":"8","new":null},{"seq":169888,"id":"CVE-2026-73415","ts":1789327132132,"field":"cvss","old":null,"new":"8"},{"seq":168683,"id":"CVE-2026-73415","ts":1789323771305,"field":"cvss","old":"8","new":null},{"seq":167478,"id":"CVE-2026-73415","ts":1789319658430,"field":"cvss","old":null,"new":"8"},{"seq":166273,"id":"CVE-2026-73415","ts":1789318698105,"field":"cvss","old":"8","new":null},{"seq":165068,"id":"CVE-2026-73415","ts":1789315763859,"field":"cvss","old":null,"new":"8"},{"seq":163863,"id":"CVE-2026-73415","ts":1789313571002,"field":"cvss","old":"8","new":null},{"seq":162658,"id":"CVE-2026-73415","ts":1789311876334,"field":"cvss","old":null,"new":"8"},{"seq":161453,"id":"CVE-2026-73415","ts":1789308663280,"field":"cvss","old":"8","new":null},{"seq":159566,"id":"CVE-2026-73415","ts":1789300447525,"field":"cvss","old":null,"new":"8"},{"seq":156555,"id":"CVE-2026-73415","ts":1789294701820,"field":"cvss","old":"8","new":null},{"seq":155350,"id":"CVE-2026-73415","ts":1789292871772,"field":"cvss","old":null,"new":"8"},{"seq":154145,"id":"CVE-2026-73415","ts":1789289725006,"field":"cvss","old":"8","new":null},{"seq":152795,"id":"CVE-2026-73415","ts":1789281637485,"field":"cvss","old":null,"new":"8"},{"seq":152435,"id":"CVE-2026-73415","ts":1789281212689,"field":"cvss","old":"8","new":null},{"seq":151396,"id":"CVE-2026-73415","ts":1789277603226,"field":"cvss","old":null,"new":"8"},{"seq":150357,"id":"CVE-2026-73415","ts":1789276200141,"field":"cvss","old":"8","new":null},{"seq":149324,"id":"CVE-2026-73415","ts":1789273797763,"field":"cvss","old":null,"new":"8"},{"seq":148291,"id":"CVE-2026-73415","ts":1789271273724,"field":"cvss","old":"8","new":null},{"seq":146323,"id":"CVE-2026-73415","ts":1789269346704,"field":"cvss","old":null,"new":"8"},{"seq":145128,"id":"CVE-2026-73415","ts":1789266296865,"field":"cvss","old":"8","new":null},{"seq":144032,"id":"CVE-2026-73415","ts":1789262579744,"field":"cvss","old":null,"new":"8"},{"seq":142936,"id":"CVE-2026-73415","ts":1789261468954,"field":"cvss","old":"8","new":null},{"seq":141767,"id":"CVE-2026-73415","ts":1789258805609,"field":"cvss","old":null,"new":"8"},{"seq":140608,"id":"CVE-2026-73415","ts":1789256682462,"field":"cvss","old":"8","new":null}]}