CVE-2021-32797High· 7.4▾ TwilightJupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.6%
2.6% → 2.7%
Untrusted notebook can execute code on load. This is a remote code execution, but requires user action to open a notebook.
Patched in the following versions: 3.1.4, 3.0.17, 2.3.2, 2.2.10, 1.2.21.
OWASP Page on Restricting Form Submissions
If you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [email protected].
Credit: Guillaume Jeanne from Google
jupyterlab < 1.2.21jupyterlab >= 2.0.0a0, < 2.2.10jupyterlab >= 2.3.0a0, < 2.3.2jupyterlab >= 3.0.0a0, < 3.0.17jupyterlab >= 3.1.0a0, < 3.1.4notebook < 5.7.11notebook >= 6.0.0, < 6.4.1Upgrade to a patched release:
jupyterlab 1.2.21jupyterlab 2.2.10jupyterlab 2.3.2jupyterlab 3.0.17jupyterlab 3.1.4notebook 5.7.11notebook 6.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-73626High· 7.5JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()
CVE-2026-73417High· 8.3jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
CVE-2026-73416Mediumjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
CVE-2026-67338Medium· 6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs
GHSA-h5v5-8746-g7mmMediumJupyterLab PluginManager lock-rule enforcement bypass
CVE-2024-39700Critical· 9.8JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…