GHSA-vmhf-c436-hxj4Medium▾ SunlitJupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A malicious PyPI package can place a javascript: URL in its [project.urls] metadata. JupyterLab's Extension Manager renders this as the extension's home-page link without validating the protocol, so a user who clicks the extension name executes attacker-controlled JavaScript in the JupyterLab origin.
One of the PyPI package's URL (jupyterlab/extensions/pypi.py) is copied straight into the homepage_url rendered by the frontend in packages/extensionmanager/src/widget.tsx#L77-L88.
best_guess_home_url = (
homepage_url # home_page / [project.urls] Homepage
or data.get("project_url")
or data.get("package_url")
or documentation_url # docs_url / [project.urls] Documentation
or source_url # [project.urls] Source Code
or bug_tracker_url # bugtrack_url / [project.urls] Bug Tracker
)
# homepage_url=best_guess_home_url
{entry.homepage_url ? (
<a href={entry.homepage_url} target="_blank" rel="noopener noreferrer" ...>
{entry.name}
</a>
) : ( <div>{entry.name}</div> )}
An attacker needs to publish a package to PyPI (no access to the target). When the package appears in a victim's extension manager list and the victim clicks the extension name, the payload runs in the JupyterLab origin.
Preconditions: Extension Manager enabled with the default PyPI source, the malicious package appears in the victim's list/search results.
Patched in 4.5.9, commits 4e61e07 and d5d961f
jupyterlab <= 4.5.8Upgrade to a patched release:
jupyterlab 4.5.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67338Medium· 6.1JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs
CVE-2026-73626High· 7.5JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()
CVE-2026-73417High· 8.3jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
CVE-2026-73416Mediumjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
GHSA-whvh-wf3x-g77jLowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
GHSA-h5v5-8746-g7mmMediumJupyterLab PluginManager lock-rule enforcement bypass