Dependency scanning
Check whether jupyterlab is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-73626
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
CVE-2026-73416
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-67338
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol
CVE-2026-42557
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
CVE-2026-42266
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
CVE-2026-40171
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2026-73417
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
GHSA-h5v5-8746-g7mm
JupyterLab PluginManager lock-rule enforcement bypass
CVE-2026-73415
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
CVE-2025-59842
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
CVE-2024-22421
JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2024-22420
JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2026-73416
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-73415
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
CVE-2026-73417
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2024-22420
JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-43805
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-43805
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2026-42557
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
CVE-2024-22421
JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2026-40171
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2024-39700
CVE-2024-39700
CVE-2021-32797
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
CVE-2025-59842
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
CVE-2021-32797
CVE-2021-32797
CVE-2026-42266
CVE-2026-42266
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes