CVE-2026-73627

NameCVE-2026-73627
DescriptionJupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked — including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144343

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jupyterlab (PTS)trixie4.0.11+ds1+~cs11.25.27-7vulnerable
forky4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4fixed
sid4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jupyterlabsource(unstable)4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-41144343

Notes

https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-h5v5-8746-g7mm
Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)

Search for package or bug name: Reporting problems