© 2025-2026 PySpect
First version without a known vulnerability: 0.9.0a0
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Fixed in: 4.6.4, 4.5.11, 0.8.4
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
Fixed in: 4.6.4, 4.5.11, 7.6.3, 0.8.4
HTML injection in JupyterLite leading to DOM Clobbering
Fixed in: 0.4.1