Executive brief
JupyterLab, a popular web-based interactive development environment for data science, is vulnerable to a security flaw where malicious settings files can execute unauthorized code. An attacker can trick a user into importing a specially crafted configuration file or, on shared systems, place the file in a location where it is automatically loaded. If exploited, an attacker could gain full access to the user's notebooks, sensitive data, and the ability to run commands on the server.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in JupyterLab due to improper validation of notebook display settings within the 'overrides.json' configuration file. Attackers can exploit this by providing a crafted settings file that contains malicious scripts, which are executed in the context of the victim's browser session when the file is imported via the Settings Editor or automatically loaded from a shared directory. Successful exploitation allows the attacker to perform actions with the victim's privileges, including reading/modifying notebooks and executing code on the notebook server or connected kernels. The issue is addressed in versions 4.6.2 and 4.5.10.
Affected products
- Project Jupyter JupyterLab >= 3.3.0, <= 4.5.9; >= 4.6.0, <= 4.6.1
Timeline
- 2026-07-21: disclosed
- 2026-07-22: advisory
References
- https://api.github.com/users/de3erve-hunter
- https://github.com/de3erve-hunter
- https://api.github.com/users/de3erve-hunter/gists%7B/gist_id%7D
- https://api.github.com/users/de3erve-hunter/repos
- https://avatars.githubusercontent.com/u/293707138?v=4
- https://api.github.com/users/de3erve-hunter/events%7B/privacy%7D