Jupyter

Jupyterlab

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 13.08.2026 22:04:31
  • Zuletzt bearbeitet 14.08.2026 17:20:32

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json ...

  • EPSS 0.49%
  • Veröffentlicht 13.08.2026 22:04:26
  • Zuletzt bearbeitet 17.08.2026 18:18:13

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, JupyterLab's PyP...

  • EPSS 0.18%
  • Veröffentlicht 13.08.2026 11:28:25
  • Zuletzt bearbeitet 13.08.2026 13:19:21

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check w...

  • EPSS 0.57%
  • Veröffentlicht 12.08.2026 19:54:00
  • Zuletzt bearbeitet 12.08.2026 21:17:40

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a ...

  • EPSS 0.18%
  • Veröffentlicht 01.08.2026 12:22:17
  • Zuletzt bearbeitet 03.08.2026 20:17:27

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metada...

  • EPSS 0.55%
  • Veröffentlicht 13.05.2026 15:08:49
  • Zuletzt bearbeitet 22.07.2026 12:17:54

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_ur...

  • EPSS 0.35%
  • Veröffentlicht 13.05.2026 15:06:14
  • Zuletzt bearbeitet 22.07.2026 12:17:56

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button el...

  • EPSS 0.22%
  • Veröffentlicht 26.09.2025 16:15:48
  • Zuletzt bearbeitet 22.10.2025 16:27:14

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupy...

  • EPSS 0.4%
  • Veröffentlicht 28.08.2024 20:15:07
  • Zuletzt bearbeitet 30.08.2024 15:56:16

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using...

Exploit
  • EPSS 1.02%
  • Veröffentlicht 16.07.2024 18:15:07
  • Zuletzt bearbeitet 04.09.2025 18:46:50

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting the...