Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3672
  • PyPI/jupyterlab
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) 19 Aug
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-3671
  • PyPI/jupyterlab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab 19 Aug
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3670
  • PyPI/jupyterlab
JupyterLab: PyPI extension blocklist package-name canonicalization bypass 19 Aug
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-pppj-hq3g-57pj
  • PyPI/jupyterlab
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) 22 Jul
  • Fix available
  • Severity - 8.6 (High)
GHSA-gx64-gj6p-pc4c
  • PyPI/jupyterlab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab 22 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-89vp-jrxv-24w8
  • PyPI/jupyterlab
JupyterLab: PyPI extension blocklist package-name canonicalization bypass 22 Jul
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-h5v5-8746-g7mm
  • PyPI/jupyterlab
JupyterLab PluginManager lock-rule enforcement bypass 22 Jul
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-whvh-wf3x-g77j
  • PyPI/jupyterlab
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`) 22 Jul
  • Fix available
  • Severity - 0.0 (None)
PYSEC-2026-2539
  • PyPI/jupyterlab-git
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2541
  • PyPI/jupyterlab-git-core
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2540
  • PyPI/jupyterlab-git
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2681
  • PyPI/notebook
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2537
  • PyPI/jupyterlab
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2538
  • PyPI/jupyterlab
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2682
  • PyPI/notebook
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2536
  • PyPI/jupyterlab
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering 13 Jul
  • Fix available
  • Severity - 8.8 (High)