BIT-jupyterlab-2026-73415

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-73415.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-jupyterlab-2026-73415
Aliases
Published
2026-08-18T10:05:56Z
Modified
2026-08-19T12:55:38Z
Summary
jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab
Details

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:python:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / jupyterlab

Package

Name
jupyterlab
Purl
pkg:bitnami/jupyterlab

Severity

  • 7.5 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.5.10
Introduced
4.6.0
Fixed
4.6.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-73415.json"