Executive brief
JupyterLab is a popular web-based interactive development environment for notebooks, code, and data. A security flaw in its plugin manager allows authenticated users to bypass administrative restrictions that were intended to lock or disable specific features. This could allow users to circumvent security hardening measures, such as data upload/download limits or other restricted actions, potentially compromising the integrity of the environment.
Technical details
JupyterLab contains an incorrect authorization vulnerability (CWE-863) and client-side enforcement of server-side security (CWE-602) in its PluginManager. Authenticated users can bypass administrative 'lock' rules by making direct requests to the `/lab/api/plugins` endpoint. This bypass is possible for child plugins of extensions covering multiple plugins or when a 'lock all' rule is active. Attackers can use this to re-enable plugins that were disabled for security hardening, such as those enforcing resource limits. The issue is patched in versions 4.6.2 and 4.5.10.
Affected products
- Jupyter jupyterlab >= 4.1.0, <= 4.5.9; >= 4.6.0, <= 4.6.1
Timeline
- 2026-07-21: disclosed
- 2026-07-22: advisory: GitHub Advisory GHSA-h5v5-8746-g7mm published
- 2026-07-22: patched