PT-2024-19411 · Unknown+1 · Jupyterlab+1

Krassowski

·

Published

2024-01-19

·

Updated

2025-03-07

·

CVE-2024-22420

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions JupyterLab versions prior to 4.0.11
Description This issue depends on user interaction by opening a malicious Markdown file using JupyterLab's preview feature. A malicious user can access any data that the attacked user has access to and perform arbitrary requests acting as the attacked user.
Recommendations For versions prior to 4.0.11, upgrade to version 4.0.11 or later. As a temporary workaround for users unable to upgrade, disable the table of contents extension by running jupyter labextension disable @jupyterlab/toc-extension:registry in the terminal.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2024-12926
BIT-JUPYTER-BASE-NOTEBOOK-2024-22420
BIT-JUPYTER-NOTEBOOK-2024-22420
BIT-JUPYTERLAB-2024-22420
CVE-2024-22420
GHSA-4M77-CMPX-VJC4
OESA-2025-1239
OESA-2025-1240
OPENSUSE-SU-2024:13605-1
OPENSUSE-SU-2024:13606-1

Affected Products

Alt Linux
Jupyterlab