Executive brief
Jupyter Notebook and JupyterLab contain a stored cross-site scripting vulnerability in the command linker feature that allows attackers to steal authentication tokens when users open malicious notebook files. An attacker can trick users into clicking seemingly legitimate controls to capture session tokens, enabling complete account takeover—including reading files, executing arbitrary code on the system, and creating shell terminals.
Technical details
The vulnerability is a stored XSS (CWE-79, CWE-601) in the CommandLinker component that processes command definitions in markdown output and notebook files. The command linker allows markup-driven navigation and command execution; attackers can chain this with the help command to create UI elements that visually masquerade as legitimate controls. When a user clicks such an element, injected JavaScript executes in the browser with the user's authentication context, stealing the REST API token. The attacker then uses this token to perform any action as that user via the REST API. Patches are available in Jupyter Notebook 7.5.6 and JupyterLab 4.5.7; the vulnerability affects all versions from 7.0.0 (notebook) and all prior versions (jupyterlab). High privileges (authenticated user) and active user interaction are required.
Affected products
- Project Jupyter Notebook 7.0.0 through 7.5.5
- Project Jupyter JupyterLab All versions through 4.5.6
Timeline
- 2026-04-30: disclosed
- 2026-04-30: patched: Jupyter Notebook 7.5.6 and JupyterLab 4.5.7