Bug 2509997 (CVE-2026-67338) - CVE-2026-67338 jupyterlab: JupyterLab: Stored cross-site scripting in Extension Manager allows arbitrary code execution
Summary: CVE-2026-67338 jupyterlab: JupyterLab: Stored cross-site scripting in Extensi...
Keywords:
Status: NEW
Alias: CVE-2026-67338
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2511389 2511390 2511424 2511425
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-01 13:02 UTC by OSIDB Bzimport
Modified: 2026-08-05 09:29 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-01 13:02:26 UTC
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.


Note You need to log in before you can comment on or make changes to this bug.