VulnSea

jupyterlab has 17 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 5. The median CVSS is 7.6 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.6
Publish → KEV
Last 90 days
9 prev 2

Products

  • jupyterlab 17
17
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

jupyterlab vulnerabilities

CVEs affecting jupyterlab, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-73626High· 7.5⚖ disputed
1mo ago

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install()

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/bloc…

Twilightjupyterlab · jupyterlabEPSS 0.21%via NVD
CVE-2026-73417High· 8.3
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an ov…

Twilightjupyterlab · jupyterlabEPSS 0.55%via NVD
CVE-2026-73416Medium
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, Jup…

Sunlitjupyterlab · jupyterlabEPSS 0.49%via NVD
CVE-2026-67338Medium· 6.1
1mo ago

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in p…

Sunlitjupyterlab · jupyterlabEPSS 0.17%via NVD
GHSA-whvh-wf3x-g77jLow
2mo ago

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-h5v5-8746-g7mmMedium
2mo ago

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

Sunlitjupyterlab · jupyterlabvia OSV
GHSA-89vp-jrxv-24w8Medium
2mo ago

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-gx64-gj6p-pc4cHigh
2mo ago

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

Twilightjupyterlab · jupyterlabvia GHSA
GHSA-pppj-hq3g-57pjHigh
2mo ago

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

Twilightjupyterlab · jupyterlabvia GHSA
GHSA-vmhf-c436-hxj4Medium
3mo ago

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

Sunlitjupyterlab · jupyterlabvia GHSA
CVE-2026-42557Critical· 9.6
4mo ago

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

Midnightjupyterlab · jupyterlabEPSS 0.37%via OSV
CVE-2025-59842Low
12mo ago

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

Sunlitjupyterlab · jupyterlabEPSS 0.24%via OSV
CVE-2024-43805High· 7.6
2y ago

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

Twilightjupyterlab · jupyterlabEPSS 0.40%via OSV
CVE-2024-39700Critical· 9.8PoC
2y ago

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` opt…

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension author…

Abyssaljupyterlab · jupyterlabEPSS 1.0%via OSV
CVE-2024-22420Medium· 6.5
2y ago

JupyterLab vulnerable to SXSS in Markdown Preview

JupyterLab vulnerable to SXSS in Markdown Preview

Sunlitjupyterlab · jupyterlabEPSS 0.57%via OSV
CVE-2024-22421High· 7.6
2y ago

JupyterLab vulnerable to potential authentication and CSRF tokens leak

JupyterLab vulnerable to potential authentication and CSRF tokens leak

Twilightjupyterlab · jupyterlabEPSS 0.67%via OSV
CVE-2021-32797High· 7.4
5y ago

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

Twilightjupyterlab · jupyterlabEPSS 2.7%via OSV
jupyterlab vulnerabilities (CVEs) · VulnSea