CVE-2026-42557
published 2026-05-13CVE-2026-42557: jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's…
PriorityP357critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.35%
27.7th percentile
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jupyter | jupyterlab | < 4.5.7 | 4.5.7 |
| jupyter | notebook | — | — |
| jupyter | notebook | >= 7.0.0 < 7.5.6 | 7.5.6 |
| jupyter | notebook | >= 7.0.0 < 7.5.6 | 7.5.6 |
| jupyterlab | jupyterlab | < 4.5.7 | 4.5.7 |
| jupyterlab | jupyterlab | >= 0 < 4.5.7 | 4.5.7 |
| mta | mta-solution-server-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-datascience-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cpu-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-minimal-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
vendor_redhat·2026-05-13·CVSS 9.6
CVE-2026-42557 [CRITICAL] CWE-79 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.
A flaw was
GHSA
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
ghsa·2026-05-06
CVE-2026-42557 [HIGH] CWE-79 JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab's HTML sanitizer allowlists `data-commandlinker-command` and `data-commandlinker-args` on `button` elements, while `CommandLinker` listens for all click events on `document.body` and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user.
### Impact
An attacker who shares a notebook or a Markdown file - via email, GitHub, or a Binder link - can invoke an arbitrary command upon a single click by th
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [epel-all]
bugzilla·2026-06-18·CVSS 9.6
CVE-2026-42557 [CRITICAL] CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [epel-all]
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [fedora-all]
bugzilla·2026-06-18·CVSS 9.6
CVE-2026-42557 [CRITICAL] CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [fedora-all]
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
bugzilla·2026-05-13·CVSS 9.6
CVE-2026-42557 [CRITICAL] CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
CVE-2026-42557 jupyterlab: JupyterLab: Arbitrary code execution via deceptive button in HTML output
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcghttps://access.redhat.com/errata/RHSA-2026:43038https://access.redhat.com/security/cve/CVE-2026-42557https://bugzilla.redhat.com/show_bug.cgi?id=2477086https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json
2026-05-13
Published