UNKNOWN PyPI

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

PYSEC-2026-3671 · BIT-jupyterlab-2026-73415 · CVE-2026-73415 · GHSA-gx64-gj6p-pc4c

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

Impact

This vulnerability allows for arbitrary code execution.

Patches

JupyterLab v4.6.2 and v4.5.10 contain the patch.

Workarounds

Disable the image viewer plugin:

jupyter labextension disable @jupyterlab/imageviewer-extension:plugin

Confirm with:

jupyter labextension list

Ready to move

Start Securing

Free, no credit card | First findings in minutes