JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
PYSEC-2026-3671 · BIT-jupyterlab-2026-73415 · CVE-2026-73415 · GHSA-gx64-gj6p-pc4c
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.
Impact
This vulnerability allows for arbitrary code execution.
Patches
JupyterLab v4.6.2 and v4.5.10 contain the patch.
Workarounds
Disable the image viewer plugin:
jupyter labextension disable @jupyterlab/imageviewer-extension:plugin
Confirm with:
jupyter labextension list
References
- WEB https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
- WEB https://github.com/jupyterlab/jupyterlab/pull/19184
- WEB https://github.com/jupyterlab/jupyterlab/pull/19185
- WEB https://github.com/jupyterlab/jupyterlab/pull/19186
- WEB https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
- WEB https://github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432
- PACKAGE https://github.com/jupyterlab/jupyterlab
- WEB https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10
- WEB https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2
- PACKAGE https://pypi.org/project/jupyterlab
- ADVISORY https://github.com/advisories/GHSA-gx64-gj6p-pc4c
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-73415
Ready to move
Start Securing
Free, no credit card | First findings in minutes