CVE-2026-40171
published 2026-05-06CVE-2026-40171: In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and…
PriorityP346high8.4CVSS 4.0
AVNACLATNPRHUIAVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.48%
38.1th percentile
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.
An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jupyter-notebook | help-extension | — | — |
| jupyter-notebook | help-extension | >= 7.0.0 < 7.5.6 | 7.5.6 |
| jupyter | notebook | — | — |
| jupyter | notebook | >= 7.0.0 < 7.5.6 | 7.5.6 |
| jupyterlab | help-extension | — | — |
| jupyterlab | help-extension | >= 0 < 4.5.7 | 4.5.7 |
| jupyterlab | jupyterlab | <= 4.5.6 | — |
| jupyterlab | jupyterlab | >= 0 < 4.5.7 | 4.5.7 |
| mta | mta-solution-server-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv4.08.4HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
vendor_redhat·2026-05-06·CVSS 8.4
CVE-2026-40171 [HIGH] CWE-79 Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.
An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication t
VulDB
jupyter notebook up to 7.5.5 cross site scripting
vuldb·2026-05-06·CVSS 8.4
CVE-2026-40171 [HIGH] jupyter notebook up to 7.5.5 cross site scripting
A vulnerability, which was classified as problematic, has been found in jupyter notebook up to 7.5.5. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-40171. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
ghsa·2026-04-30
CVE-2026-40171 [HIGH] CWE-601 Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
### Impact
A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).
The vulnerability enables complete account takeover through the Jupyter REST API, allowing the attacker to:
1. Read all files
2. Modify/create files
3. Access running kernels and execute arbitrary code
4. Create terminals for shell access
### Patches
Jupyter Notebook 7.5.6 and JupyterLab 4.5.7 include patches for this vulnerability.
### Workarounds
The help extension can be disabled via CLI:
```
jupyter l
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [epel-all]
bugzilla·2026-06-22·CVSS 8.4
CVE-2026-40171 [HIGH] CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [epel-all]
CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [fedora-all]
bugzilla·2026-06-22·CVSS 8.4
CVE-2026-40171 [HIGH] CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [fedora-all]
CVE-2026-40171 jupyterlab: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40171 Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
bugzilla·2026-05-06·CVSS 8.4
CVE-2026-40171 [HIGH] CVE-2026-40171 Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
CVE-2026-40171 Jupyter Notebook: JupyterLab: @jupyter-notebook/help-extension: @jupyterlab/help-extension: Jupyter Notebook and JupyterLab: Session takeover via stored cross-site scripting
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.
An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's
2026-05-06
Published