BIT-jupyterlab-2026-42266

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-42266.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-jupyterlab-2026-42266
Aliases
Published
2026-05-15T08:42:28Z
Modified
2026-09-08T08:47:30Z
Summary
JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
Details

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:python:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / jupyterlab

Package

Name
jupyterlab
Purl
pkg:bitnami/jupyterlab

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.5.7

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/jupyterlab/BIT-jupyterlab-2026-42266.json"