{"id":"CVE-2026-73626","title":"JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()","summary":"JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/bloc…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"vendor":"jupyterlab","product":"jupyterlab","affected":["jupyterlab >= 4.6.0, < 4.6.2","jupyterlab < 4.5.10"],"patched":["jupyterlab 4.6.2","jupyterlab 4.5.10"],"published":"2026-08-13","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:36:38.867","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-73626","references":[{"url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/jupyterlab-before-authentication-bypass-via-pypiextensionmanager","label":"disclosure@vulncheck.com"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"url":"https://github.com/jupyterlab/jupyterlab"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"}],"tags":["nvd","osv","pip","score-dispute"],"epss":0.00214,"epssPercentile":0.12058,"aliases":["GHSA-whvh-wf3x-g77j"],"ecosystem":"pip","scores":{"nvd":7.5,"osv":0},"ingestedAt":"2026-08-14T19:18:45.720Z","slug":"CVE-2026-73626","body":"## Overview\n\nJupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-73626)\n\nAffected packages:\n\n- `jupyterlab >= 4.6.0, < 4.6.2`\n- `jupyterlab < 4.5.10`\n\nPatched in:\n\n- `jupyterlab 4.6.2`\n- `jupyterlab 4.5.10`\n\nSource: https://osv.dev/vulnerability/GHSA-whvh-wf3x-g77j","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":201900,"id":"CVE-2026-73626","ts":1789399980119,"field":"cvss","old":"0","new":"7.5"},{"seq":201899,"id":"CVE-2026-73626","ts":1789399980119,"field":"severity","old":"none","new":"high"},{"seq":200630,"id":"CVE-2026-73626","ts":1789397539262,"field":"cvss","old":"7.5","new":"0"},{"seq":200629,"id":"CVE-2026-73626","ts":1789397539262,"field":"severity","old":"high","new":"none"},{"seq":199344,"id":"CVE-2026-73626","ts":1789395458377,"field":"cvss","old":"0","new":"7.5"},{"seq":199343,"id":"CVE-2026-73626","ts":1789395458377,"field":"severity","old":"none","new":"high"},{"seq":198589,"id":"CVE-2026-73626","ts":1789392137812,"field":"cvss","old":"7.5","new":"0"},{"seq":198588,"id":"CVE-2026-73626","ts":1789392137812,"field":"severity","old":"high","new":"none"},{"seq":198544,"id":"CVE-2026-73626","ts":1789392065774,"field":"cvss","old":"0","new":"7.5"},{"seq":198543,"id":"CVE-2026-73626","ts":1789392065774,"field":"severity","old":"none","new":"high"},{"seq":196335,"id":"CVE-2026-73626","ts":1789383707121,"field":"cvss","old":"7.5","new":"0"},{"seq":196334,"id":"CVE-2026-73626","ts":1789383707121,"field":"severity","old":"high","new":"none"},{"seq":195264,"id":"CVE-2026-73626","ts":1789380543968,"field":"cvss","old":"0","new":"7.5"},{"seq":195263,"id":"CVE-2026-73626","ts":1789380543968,"field":"severity","old":"none","new":"high"},{"seq":194051,"id":"CVE-2026-73626","ts":1789378650777,"field":"cvss","old":"7.5","new":"0"},{"seq":194050,"id":"CVE-2026-73626","ts":1789378650777,"field":"severity","old":"high","new":"none"},{"seq":192838,"id":"CVE-2026-73626","ts":1789376481198,"field":"cvss","old":"0","new":"7.5"},{"seq":192837,"id":"CVE-2026-73626","ts":1789376481198,"field":"severity","old":"none","new":"high"},{"seq":191625,"id":"CVE-2026-73626","ts":1789373557640,"field":"cvss","old":"7.5","new":"0"},{"seq":191624,"id":"CVE-2026-73626","ts":1789373557640,"field":"severity","old":"high","new":"none"},{"seq":190410,"id":"CVE-2026-73626","ts":1789369421631,"field":"cvss","old":"0","new":"7.5"},{"seq":190409,"id":"CVE-2026-73626","ts":1789369421631,"field":"severity","old":"none","new":"high"},{"seq":189197,"id":"CVE-2026-73626","ts":1789368349164,"field":"cvss","old":"7.5","new":"0"},{"seq":189196,"id":"CVE-2026-73626","ts":1789368349164,"field":"severity","old":"high","new":"none"},{"seq":187980,"id":"CVE-2026-73626","ts":1789365204338,"field":"cvss","old":"0","new":"7.5"},{"seq":187979,"id":"CVE-2026-73626","ts":1789365204338,"field":"severity","old":"none","new":"high"},{"seq":186767,"id":"CVE-2026-73626","ts":1789363413739,"field":"cvss","old":"7.5","new":"0"},{"seq":186766,"id":"CVE-2026-73626","ts":1789363413739,"field":"severity","old":"high","new":"none"},{"seq":185553,"id":"CVE-2026-73626","ts":1789361185646,"field":"cvss","old":"0","new":"7.5"},{"seq":185552,"id":"CVE-2026-73626","ts":1789361185646,"field":"severity","old":"none","new":"high"},{"seq":184340,"id":"CVE-2026-73626","ts":1789358276886,"field":"cvss","old":"7.5","new":"0"},{"seq":184339,"id":"CVE-2026-73626","ts":1789358276886,"field":"severity","old":"high","new":"none"},{"seq":182591,"id":"CVE-2026-73626","ts":1789354278825,"field":"cvss","old":"0","new":"7.5"},{"seq":182590,"id":"CVE-2026-73626","ts":1789354278825,"field":"severity","old":"none","new":"high"},{"seq":181384,"id":"CVE-2026-73626","ts":1789353249885,"field":"cvss","old":"7.5","new":"0"},{"seq":181383,"id":"CVE-2026-73626","ts":1789353249885,"field":"severity","old":"high","new":"none"},{"seq":180177,"id":"CVE-2026-73626","ts":1789350232165,"field":"cvss","old":"0","new":"7.5"},{"seq":180176,"id":"CVE-2026-73626","ts":1789350232165,"field":"severity","old":"none","new":"high"},{"seq":178970,"id":"CVE-2026-73626","ts":1789348226114,"field":"cvss","old":"7.5","new":"0"},{"seq":178969,"id":"CVE-2026-73626","ts":1789348226114,"field":"severity","old":"high","new":"none"},{"seq":177763,"id":"CVE-2026-73626","ts":1789346346628,"field":"cvss","old":"0","new":"7.5"},{"seq":177762,"id":"CVE-2026-73626","ts":1789346346628,"field":"severity","old":"none","new":"high"},{"seq":176556,"id":"CVE-2026-73626","ts":1789343132410,"field":"cvss","old":"7.5","new":"0"},{"seq":176555,"id":"CVE-2026-73626","ts":1789343132410,"field":"severity","old":"high","new":"none"},{"seq":174673,"id":"CVE-2026-73626","ts":1789334843544,"field":"cvss","old":"0","new":"7.5"},{"seq":174672,"id":"CVE-2026-73626","ts":1789334843544,"field":"severity","old":"none","new":"high"},{"seq":173468,"id":"CVE-2026-73626","ts":1789333625348,"field":"cvss","old":"7.5","new":"0"},{"seq":173467,"id":"CVE-2026-73626","ts":1789333625348,"field":"severity","old":"high","new":"none"},{"seq":172282,"id":"CVE-2026-73626","ts":1789331070361,"field":"cvss","old":"0","new":"7.5"},{"seq":172281,"id":"CVE-2026-73626","ts":1789331070361,"field":"severity","old":"none","new":"high"}]}