Junglewise Threat Intelligence

CVE-2026-73627: JupyterLab plugin manager lock-rule enforcement bypass

CVE-2026-73627 · Severity: info · CVSS 6 · Published 2026-08-13

Technologies: Project Jupyter JupyterLab. Vendors: Project Jupyter.

Executive brief

JupyterLab is a web-based interactive development environment widely used for data science and computing. Administrators can lock plugins to enforce security policies (e.g., restrict upload/download capabilities). An authenticated attacker can bypass these administrative locks by making direct API requests, enabling or disabling plugins at will and circumventing security restrictions—potentially exposing data or enabling unauthorized operations.

Technical details

This vulnerability is a server-side enforcement gap in JupyterLab's plugin manager affecting versions 4.1.0–4.5.9 and 4.6.0–4.6.1. An authenticated user can send direct requests to the /lab/api/plugins endpoint to bypass administrator lock rules, including multi-plugin extensions and "lock all" mechanisms. The attack requires network access and valid authentication credentials; no user interaction is needed. An attacker can toggle plugin states to circumvent hardening measures such as upload/download limits. Patches are available in versions 4.5.10 and 4.6.2.

Affected products

  • Project Jupyter JupyterLab >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1

Timeline

  • 2026-07-21: disclosed
  • 2026-08-13: advisory: Published on NVD
  • 2026: patched: Fixed in JupyterLab 4.5.10 and 4.6.2

References

Related threats