Vulnerabilidades en jupyterlab
18 resultadosAnálisis Vexday
JupyterLab apresenta 12 vulnerabilidades catalogadas, sendo 2 críticas, mas nenhuma sob ataque ativo conhecido até o momento. A fraqueza dominante é injeção de scripts (CWE-79), com 5 vulnerabilidades publicadas nos últimos 90 dias, indicando descobertas recentes que demandam atenção à aplicação de patches.
CVE-2021-32797HIGHJupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>EPSS 2.7%CVE-2024-39700CRITICALRemote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub ActionEPSS 1.0%CVE-2024-22421HIGHPotential authentication and CSRF tokens leak in JupyterLabEPSS 0.7%CVE-2026-42266HIGHJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.EPSS 0.6%CVE-2025-30370HIGHjupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"EPSS 0.6%CVE-2026-73415HIGHjupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tabEPSS 0.6%CVE-2024-22420MEDIUMStored cross site scripting in Markdown Preview in JupyterLabEPSS 0.6%CVE-2026-73417HIGHJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)EPSS 0.6%CVE-2026-54527CRITICALJupyterLab Git: Stored XSS leading to RCEEPSS 0.5%CVE-2026-73416MEDIUMjupyterlab: PyPI extension blocklist package-name canonicalization bypassEPSS 0.5%CVE-2026-40171HIGHJupyter Notebook and JupyterLab token theft via stored XSS in help command linkerEPSS 0.5%CVE-2026-54528HIGHjupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded DirectoriesEPSS 0.4%CVE-2024-43805HIGHHTML injection in Jupyter Notebook and JupyterLab leading to DOM ClobberingEPSS 0.4%CVE-2026-42557HIGHjupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted contentEPSS 0.4%CVE-2026-73627MEDIUMJupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement BypassEPSS 0.2%CVE-2025-59842LOWJupyterLab LaTeX typesetter links did not enforce `noopener` attributeEPSS 0.2%CVE-2026-73626HIGHJupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManagerEPSS 0.2%CVE-2026-67338MEDIUMJupyterLab before 4.5.9 Stored XSS via Extension ManagerEPSS 0.2%