CVE-2026-67338

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 13:17

Updated : 2026-09-09 20:36


NVD link : CVE-2026-67338

Mitre link : CVE-2026-67338

CVE.ORG link : CVE-2026-67338


JSON object : View

Products Affected

No product.

CWE
CWE-84

Improper Neutralization of Encoded URI Schemes in a Web Page