© 2025-2026 PySpect
First version without a known vulnerability: 4.6.0a0
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Fixed in: 4.6.2, 4.5.10
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
Fixed in: 4.6.2, 4.5.10
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Fixed in: 4.6.2, 4.5.10
JupyterLab PluginManager lock-rule enforcement bypass
Fixed in: 4.6.2, 4.5.10
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
Fixed in: 4.6.2, 4.5.10
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
Fixed in: 4.5.9
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Fixed in: 4.5.7, 7.5.6
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
Fixed in: 4.5.7
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Fixed in: 7.5.6, 4.5.7
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Fixed in: 4.4.8
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
Fixed in: 3.6.8, 7.2.2, 4.2.5
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the `main` branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.
Fixed in: 4.3.0
JupyterLab vulnerable to potential authentication and CSRF tokens leak
Fixed in: 4.0.11, 3.6.7, 7.0.7
JupyterLab vulnerable to SXSS in Markdown Preview
Fixed in: 4.0.11, 7.0.7
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Fixed in: 1.2.21, 2.2.10, 2.3.2, 3.0.17, 3.1.4, 5.7.11, 6.4.1, 504825938c0abfa2fb8ff8d529308830a5ae42ed