CVE-2026-73415

NameCVE-2026-73415
Descriptionjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144343

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jupyterlab (PTS)trixie4.0.11+ds1+~cs11.25.27-7vulnerable
forky, sid4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jupyterlabsource(unstable)4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-41144343

Notes

https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
https://github.com/jupyterlab/jupyterlab/pull/19186
Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)

Search for package or bug name: Reporting problems