CVE-2026-40171High· 8.8▾ TwilightJupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.5%
Last analysed / modified upstream
8.8 → —
— → 8.8
8.8 → —
— → 8.8
8.8 → —
— → 8.8
8.8 → —
— → 8.8
8.8 → —
— → 8.8
8.8 → —
— → 8.8
A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).
The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
Jupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability.
The help extension can be disabled via CLI:
jupyter labextension disable @jupyter-notebook/help-extension
jupyter labextension disable @jupyterlab/help-extension
The patched versions include a toggle to disable the command linker functionality altogether, for example via overrides.json:
{
"@jupyterlab/apputils-extension:sanitizer": {
"allowCommandLinker": false
}
}
Reported by Daniel Teixeira - NVIDIA AI Red Team
@jupyter-notebook/help-extension >= 7.0.0, < 7.5.6notebook >= 7.0.0, < 7.5.6jupyterlab < 4.5.7@jupyterlab/help-extension < 4.5.7Upgrade to a patched release:
@jupyter-notebook/help-extension 7.5.6notebook 7.5.6jupyterlab 4.5.7@jupyterlab/help-extension 4.5.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-9644Medium· 5.4Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41182Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2019-1973Medium· 4.8A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface