JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-01 13:17
Updated : 2026-09-09 20:36
NVD link : CVE-2026-67338
Mitre link : CVE-2026-67338
CVE.ORG link : CVE-2026-67338
JSON object : View
Products Affected
No product.
CWE
CWE-84
Improper Neutralization of Encoded URI Schemes in a Web Page
