Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Reported upstream: https://github.com/jupyterlab/jupyterlab/issues/18394
Fixed upstream in: https://github.com/jupyterlab/jupyterlab/commit/605c74633b362be94ee620a9b59792fa92a2914a