CVE-2026-67338
published 2026-08-01CVE-2026-67338: JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.18%
7.2th percentile
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jupyterlab | jupyterlab | < 4.5.9 | 4.5.9 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
jupyter JupyterLab up to 4.5.8 Extension Manager cross site scripting (EUVD-2026-51849)
vuldb·2026-08-01·CVSS 6.1
CVE-2026-67338 [MEDIUM] jupyter JupyterLab up to 4.5.8 Extension Manager cross site scripting (EUVD-2026-51849)
A vulnerability was found in jupyter JupyterLab up to 4.5.8. It has been classified as problematic. This affects an unknown part of the component Extension Manager. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-67338. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs.
ghsa_unreviewed·2026-08-01
CVE-2026-67338 [MEDIUM] CWE-84 JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs.
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4https://www.vulncheck.com/advisories/jupyterlab-before-stored-xss-via-extension-manager
2026-08-01
Published