BIT-jupyterlab-2026-42557

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-42557.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-jupyterlab-2026-42557
Aliases
Published
2026-05-15T08:42:30.212Z
Modified
2026-05-15T11:11:10.345567780Z
Summary
jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content
Details

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.

Database specific
{
    "cpes": [
        "cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / jupyterlab

Package

Name
jupyterlab
Purl
pkg:bitnami/jupyterlab

Severity

  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.7

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-42557.json"