PT-2026-37256 · Project Jupyter · Jupyterlab

Pmcao

·

Published

2026-05-05

·

Updated

2026-05-21

·

CVE-2026-42266

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JupyterLab versions prior to 4.5.7
Description The PyPI Extension Manager does not correctly enforce the allowed extensions uris allow-list, allowing the installation of packages not listed on the default PyPI index. This issue affects deployments that use allow-lists to restrict package installation, have disabled kernels and terminals, or utilize multi-tenant configurations not set up for untrusted users. An authenticated attacker can exploit this to escalate privileges, potentially leading to data exfiltration, lateral movement within the network, and persistent compromise of the server infrastructure.
Recommendations Update to version 4.5.7. As a temporary workaround, switch to a read-only extension manager by using the command line option --LabApp.extension manager=readonly or the traitlet c.LabApp.extension manager = 'readonly'.

Fix

Argument Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JUPYTERLAB-2026-42266
CVE-2026-42266
GHSA-37W4-HWHX-4RC4
OPENSUSE-SU-2026:10748-1
PYSEC-2026-164

Affected Products

Jupyterlab