Jupyterlab
21 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Jupyterlab, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Jupyterlab CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 3 |
| 2026-06 | 1 |
| 2026-07 | 5 |
| 2026-08 | 6 |
| 2026-09 | 0 |
Severity
How the 21 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High5
- Medium3
Latest CVEs
The 15 most recently published vulnerabilities affecting Jupyterlab.
- CVE-2026-73417JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)—
- CVE-2026-73416jupyterlab: PyPI extension blocklist package-name canonicalization bypass—
- CVE-2026-73627JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass—
- CVE-2026-73626JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager7.5
- CVE-2026-73415jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab—
- CVE-2026-67338JupyterLab before 4.5.9 Stored XSS via Extension Manager6.1
- GHSA-pppj-hq3g-57pjJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)—
- GHSA-gx64-gj6p-pc4cJupyterLab: Image viewer allows XSS when opening malicious image in new browser tab—
- GHSA-89vp-jrxv-24w8JupyterLab: PyPI extension blocklist package-name canonicalization bypass—
- GHSA-h5v5-8746-g7mmJupyterLab PluginManager lock-rule enforcement bypass—
- GHSA-whvh-wf3x-g77jJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)—
- GHSA-vmhf-c436-hxj4JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol—
- CVE-2026-42266JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.8.8
- CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content9.6
- CVE-2026-40171Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker—
Product grouping is registry-driven, with AI assist and human review. How it works