UBUNTU-CVE-2026-102831

Source
https://ubuntu.com/security/CVE-2026-102831
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-102831
Upstream
Published
2026-09-29T19:17:00Z
Modified
2026-10-01T00:26:11Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.

References

Affected packages

Ubuntu:18.04:LTS
jupyter-notebook

Package

Name
jupyter-notebook
Purl
pkg:deb/ubuntu/jupyter-notebook?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.2.3-4
5.*
5.1.0-2
5.2.1-2
5.2.2-1
5.2.2-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyter-notebook",
            "binary_version": "5.2.2-1ubuntu0.1"
        },
        {
            "binary_name": "python-notebook",
            "binary_version": "5.2.2-1ubuntu0.1"
        },
        {
            "binary_name": "python3-notebook",
            "binary_version": "5.2.2-1ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"
Ubuntu:20.04:LTS
jupyter-notebook

Package

Name
jupyter-notebook
Purl
pkg:deb/ubuntu/jupyter-notebook?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.7.8-1
6.*
6.0.0-1
6.0.0-2
6.0.2-1
6.0.3-1
6.0.3-2
6.0.3-2ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyter-notebook",
            "binary_version": "6.0.3-2ubuntu0.1"
        },
        {
            "binary_name": "python3-notebook",
            "binary_version": "6.0.3-2ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"
Ubuntu:26.04:LTS
jupyter-notebook

Package

Name
jupyter-notebook
Purl
pkg:deb/ubuntu/jupyter-notebook?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.13-5ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyter-notebook",
            "binary_version": "6.4.13-5ubuntu0.1"
        },
        {
            "binary_name": "python3-notebook",
            "binary_version": "6.4.13-5ubuntu0.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"
jupyterlab

Package

Name
jupyterlab
Purl
pkg:deb/ubuntu/jupyterlab?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0.11+ds1+~cs11.25.27-7
4.0.11+ds1+~cs11.25.27-8
4.0.11+ds1+~cs11.25.27-9

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyterlab",
            "binary_version": "4.0.11+ds1+~cs11.25.27-9"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"
Ubuntu:Pro:22.04:LTS
jupyter-notebook

Package

Name
jupyter-notebook
Purl
pkg:deb/ubuntu/jupyter-notebook?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.2.0-1
6.4.5-2
6.4.5-3
6.4.5-4
6.4.8-1
6.4.8-1ubuntu0.1
6.4.8-1ubuntu0.1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyter-notebook",
            "binary_version": "6.4.8-1ubuntu0.1+esm1"
        },
        {
            "binary_name": "python3-notebook",
            "binary_version": "6.4.8-1ubuntu0.1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"
Ubuntu:Pro:24.04:LTS
jupyter-notebook

Package

Name
jupyter-notebook
Purl
pkg:deb/ubuntu/jupyter-notebook?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.12-2.2
6.4.12-2.2ubuntu1
6.4.12-2.2ubuntu1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "jupyter-notebook",
            "binary_version": "6.4.12-2.2ubuntu1+esm1"
        },
        {
            "binary_name": "python3-notebook",
            "binary_version": "6.4.12-2.2ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-102831.json"