pypi

jupyterlab

View on pypi registry
26 Total advisories
26 Vulnerabilities
0 Malware

Dependency scanning

Check whether jupyterlab is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

NONE 0.0
PyPI

CVE-2026-73626

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

UNKNOWN
PyPI

CVE-2026-73416

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

UNKNOWN
PyPI

CVE-2026-67338

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

CRITICAL 9.6
PyPI

CVE-2026-42557

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

HIGH 8.8
PyPI

CVE-2026-42266

JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request

UNKNOWN
npm

CVE-2026-40171

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

UNKNOWN
PyPI

CVE-2026-73417

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

UNKNOWN
PyPI

GHSA-h5v5-8746-g7mm

JupyterLab PluginManager lock-rule enforcement bypass

UNKNOWN
PyPI

CVE-2026-73415

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

UNKNOWN
PyPI

CVE-2025-59842

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

HIGH 7.6
PyPI

CVE-2024-22421

JupyterLab vulnerable to potential authentication and CSRF tokens leak

MEDIUM 6.5
PyPI

CVE-2024-22420

JupyterLab vulnerable to SXSS in Markdown Preview

UNKNOWN
PyPI

CVE-2026-73416

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

UNKNOWN
PyPI

CVE-2026-73415

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

UNKNOWN
PyPI

CVE-2026-73417

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

MEDIUM 6.5
PyPI

CVE-2024-22420

JupyterLab vulnerable to SXSS in Markdown Preview

HIGH 7.6
PyPI

CVE-2024-43805

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HIGH 7.6
PyPI

CVE-2024-43805

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

CRITICAL 9.6
PyPI

CVE-2026-42557

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

HIGH 7.6
PyPI

CVE-2024-22421

JupyterLab vulnerable to potential authentication and CSRF tokens leak

UNKNOWN
PyPI

CVE-2026-40171

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

CRITICAL 9.8
PyPI

CVE-2024-39700

CVE-2024-39700

HIGH 7.4
PyPI

CVE-2021-32797

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

UNKNOWN
PyPI

CVE-2025-59842

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute

UNKNOWN
PyPI

CVE-2021-32797

CVE-2021-32797

HIGH 8.8
PyPI

CVE-2026-42266

CVE-2026-42266

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes