PT-2026-36305 · Project Jupyter · Jupyterlab+1

Dtrops

·

Published

2026-04-30

·

Updated

2026-05-11

·

CVE-2026-40171

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Jupyter Notebook versions prior to 7.5.6 JupyterLab versions prior to 4.5.7
Description A stored Cross-Site Scripting (XSS) issue allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements designed to look like legitimate controls. This can lead to complete account takeover via the Jupyter REST API, enabling the attacker to read, modify, or create files, access running kernels to execute arbitrary code, and create terminals for shell access.
Recommendations Update Jupyter Notebook to version 7.5.6. Update JupyterLab to version 4.5.7. Disable the help extension via CLI using jupyter labextension disable @jupyter-notebook/help-extension and jupyter labextension disable @jupyterlab/help-extension. Disable the command linker functionality in overrides.json by setting @jupyterlab/apputils-extension:sanitizer with allowCommandLinker set to false.

Fix

XSS

Open Redirect

Weakness Enumeration

Related Identifiers

BIT-JUPYTER-BASE-NOTEBOOK-2026-40171
BIT-JUPYTER-NOTEBOOK-2026-40171
BIT-JUPYTERLAB-2026-40171
CVE-2026-40171
GHSA-RCH3-82JR-F9W9
OPENSUSE-SU-2026:10748-1
OPENSUSE-SU-2026:10749-1

Affected Products

Jupyter Notebook
Jupyterlab