{"id":"GHSA-h5v5-8746-g7mm","title":"JupyterLab PluginManager lock-rule enforcement bypass","summary":"JupyterLab PluginManager lock-rule enforcement bypass","severity":"medium","vendor":"jupyterlab","product":"jupyterlab","ecosystem":"pip","affected":["jupyterlab >= 4.6.0, < 4.6.2","jupyterlab >= 4.1.0, < 4.5.10"],"patched":["jupyterlab 4.6.2","jupyterlab 4.5.10"],"published":"2026-07-22","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:52.342232928Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-h5v5-8746-g7mm","references":[{"url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19184"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19185"},{"url":"https://github.com/jupyterlab/jupyterlab/pull/19186"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432"},{"url":"https://github.com/jupyterlab/jupyterlab"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2"},{"url":"https://github.com/advisories/GHSA-h5v5-8746-g7mm"}],"tags":["osv","pip","ghsa"],"cwe":["CWE-602","CWE-863"],"ingestedAt":"2026-07-23T00:08:38.854Z","slug":"GHSA-h5v5-8746-g7mm","body":"## Overview\n\nJupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.\n\n### Impact\n\nUsers could workaround the plugin manager lock rules via direct API access for either:\n- child plugins of extensions covering multiple plugins\n- when \"lock all\" was issued by the administrator\n\nThe integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms.\n\n### Patches\n\nJupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch.\n\nUsers of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too.\n\n### Workarounds\n\nManually lock all plugins that should be locked. The core plugin identifiers can be found in [the documentation](https://jupyterlab.readthedocs.io/en/latest/extension/extension_points.html#core-plugins) and identifiers for all installed extensions are listed in the [Plugin Manager](https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#managing-plugins-with-plugin-manager).\n\n## Affected packages\n\n- `jupyterlab >= 4.6.0, < 4.6.2`\n- `jupyterlab >= 4.1.0, < 4.5.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `jupyterlab 4.6.2`\n- `jupyterlab 4.5.10`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}