{"id":"GHSA-vmhf-c436-hxj4","title":"JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol","summary":"JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol","severity":"medium","cwe":["CWE-84"],"vendor":"jupyterlab","product":"jupyterlab","affected":["jupyterlab <= 4.5.8"],"patched":["jupyterlab 4.5.9"],"published":"2026-06-19","updated":"2026-06-19","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-vmhf-c436-hxj4","references":[{"url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6"},{"url":"https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12"},{"url":"https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.9"},{"url":"https://github.com/advisories/GHSA-vmhf-c436-hxj4"}],"tags":["ghsa","pip"],"ingestedAt":"2026-06-22T15:52:21.099Z","ecosystem":"pip","slug":"GHSA-vmhf-c436-hxj4","body":"## Overview\n\nA malicious PyPI package can place a `javascript:` URL in its `[project.urls]` metadata. JupyterLab's Extension Manager renders this as the extension's home-page link without validating the protocol, so a user who clicks the extension name executes attacker-controlled JavaScript in the JupyterLab origin.\n\n### Details\n\nOne of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the `homepage_url` rendered by the frontend in packages/extensionmanager/src/widget.tsx#L77-L88.\n\n```python\nbest_guess_home_url = (\n    homepage_url            # home_page / [project.urls] Homepage\n    or data.get(\"project_url\")\n    or data.get(\"package_url\")\n    or documentation_url    # docs_url / [project.urls] Documentation\n    or source_url           # [project.urls] Source Code\n    or bug_tracker_url      # bugtrack_url / [project.urls] Bug Tracker\n)\n\n# homepage_url=best_guess_home_url\n```\n\n```tsx\n{entry.homepage_url ? (\n  <a href={entry.homepage_url} target=\"_blank\" rel=\"noopener noreferrer\" ...>\n    {entry.name}\n  </a>\n) : ( <div>{entry.name}</div> )}\n```\n\n### Impact\n\nAn attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin.\n\nPreconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results.\n\n### Patches\nPatched in [4.5.9](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.9), commits [4e61e07](https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6) and [d5d961f](https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12)\n\n## Affected packages\n\n- `jupyterlab <= 4.5.8`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `jupyterlab 4.5.9`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}