CVE-2026-42266
published 2026-05-13CVE-2026-42266: JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the…
PriorityP354high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.55%
43.1th percentile
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jupyter | jupyterlab | >= 4.0.0 < 4.5.7 | 4.5.7 |
| jupyterlab | jupyterlab | — | — |
| jupyterlab | jupyterlab | >= 4.0.0 < 4.5.7 | 4.5.7 |
| mta | mta-solution-server-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cpu-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch210-py312-rhel9 | — | — |
| rhoai | odh-th06-cuda130-torch291-py312-rhel9 | — | — |
| rhoai | odh-th06-rocm64-torch291-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
vendor_redhat·2026-05-13·CVSS 8.8
CVE-2026-42266 [HIGH] CWE-88 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
A flaw was found in JupyterLab, an extensible environment for interactive computing. The PyPI Extension Manager, responsible for installing extensions, failed to properly enforce its allow-list of approved extensions. This vulnerability allowed for the installation of unau
GHSA
JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
ghsa·2026-05-05
CVE-2026-42266 [HIGH] CWE-20 JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
The allow-list of extensions that can be installed from PyPI Extension Manager (`allowed_extensions_uris`) is not correctly enforced by JupyterLab prior to 4.5.X. The PyPI Extension Manager was not contained to packages listed on the default PyPI index.
This has security implications for deployments that:
- have allow-listed specific extensions with aim to prevent users from installing packages
- have the kernel and terminals disabled or delegated to remote hosts (thus no access to install packages in the single-user server environment)
- have multi-tenant deployments that is not configured for untrusted users (as per documented on JupyterHub https://jupyterh
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [fedora-all]
bugzilla·2026-06-26·CVSS 8.8
CVE-2026-42266 [HIGH] CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [fedora-all]
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [epel-all]
bugzilla·2026-06-26·CVSS 8.8
CVE-2026-42266 [HIGH] CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [epel-all]
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
bugzilla·2026-05-13·CVSS 8.8
CVE-2026-42266 [HIGH] CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
CVE-2026-42266 jupyterlab: JupyterLab: Arbitrary code execution due to improper enforcement of extension allow-list
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.htmlhttps://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementationshttps://access.redhat.com/errata/RHSA-2026:43038https://access.redhat.com/security/cve/CVE-2026-42266https://bugzilla.redhat.com/show_bug.cgi?id=2477072https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42266.json
2026-05-13
Published