{"schema_version":1,"title":"jupyterlab (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 12 vulnerabilities in jupyterlab (PyPI): 0 in the last 7 days and 9 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-73415, was published on 19 August 2026.","url":"https://junglewise.ai/threats/technologies/pypi-jupyterlab","json_url":"https://junglewise.ai/threats/technologies/pypi-jupyterlab.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-jupyterlab","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":12,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":11},"latest":[{"cve":"CVE-2026-73415","cvss":4,"epss":0.0074,"slug":"cve-2026-73415-jupyterlab-image-viewer-allows-xss-when-opening-malicious-image","title":"PYSEC-2026-3671 - JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab","severity":"medium","exploited":false,"published_at":"2026-08-19T11:56:25.364725+00:00","url":"https://junglewise.ai/threats/cve-2026-73415-jupyterlab-image-viewer-allows-xss-when-opening-malicious-image"},{"cve":"CVE-2026-73417","cvss":4,"epss":0.0075,"slug":"cve-2026-73417-jupyterlab-arbitrary-code-execution-via-malicious-overrides-json","title":"JupyterLab arbitrary code execution via malicious overrides.json","severity":"medium","exploited":false,"published_at":"2026-08-13T22:17:26.133+00:00","url":"https://junglewise.ai/threats/cve-2026-73417-jupyterlab-arbitrary-code-execution-via-malicious-overrides-json"},{"cve":"CVE-2026-73416","cvss":4,"epss":0.0066,"slug":"cve-2026-73416-jupyterlab-extension-blocklist-bypass-via-package-name-variant","title":"JupyterLab extension blocklist bypass via package name variant","severity":"medium","exploited":false,"published_at":"2026-08-13T22:17:25.963+00:00","url":"https://junglewise.ai/threats/cve-2026-73416-jupyterlab-extension-blocklist-bypass-via-package-name-variant"},{"cve":"CVE-2026-40171","cvss":4,"epss":0.0066,"slug":"cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss","title":"PYSEC-2026-2682 - Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","severity":"medium","exploited":false,"published_at":"2026-07-13T15:02:55.67876+00:00","url":"https://junglewise.ai/threats/cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss"},{"cve":"CVE-2024-43805","cvss":3.1,"epss":0.004,"slug":"cve-2024-43805-html-injection-in-jupyter-notebook-and-jupyterlab-leading-to-dom","title":"PYSEC-2026-2536 - HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.612035+00:00","url":"https://junglewise.ai/threats/cve-2024-43805-html-injection-in-jupyter-notebook-and-jupyterlab-leading-to-dom"},{"cve":"CVE-2024-22421","cvss":3.1,"epss":0.0067,"slug":"cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens","title":"PYSEC-2026-2534 - JupyterLab vulnerable to potential authentication and CSRF tokens leak","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.685378+00:00","url":"https://junglewise.ai/threats/cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens"},{"cve":"CVE-2024-22420","cvss":3.1,"epss":0.0057,"slug":"cve-2024-22420-jupyterlab-vulnerable-to-sxss-in-markdown-preview","title":"PYSEC-2026-2535 - JupyterLab vulnerable to SXSS in Markdown Preview","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.558089+00:00","url":"https://junglewise.ai/threats/cve-2024-22420-jupyterlab-vulnerable-to-sxss-in-markdown-preview"},{"cve":"CVE-2025-59842","cvss":4,"epss":0.0024,"slug":"cve-2025-59842-jupyterlab-latex-typesetter-links-did-not-enforce-noopener","title":"PYSEC-2026-1482 - JupyterLab LaTeX typesetter links did not enforce `noopener` attribute","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:05.847517+00:00","url":"https://junglewise.ai/threats/cve-2025-59842-jupyterlab-latex-typesetter-links-did-not-enforce-noopener"},{"cve":"CVE-2021-32797","cvss":3.1,"epss":0.0266,"slug":"cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action","title":"PYSEC-2026-688 - JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:10.480332+00:00","url":"https://junglewise.ai/threats/cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action"},{"cve":"CVE-2026-42557","cvss":9.6,"epss":0.0072,"slug":"cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer","title":"Jupyter JupyterLab arbitrary command execution via HTML sanitizer bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T16:16:48.167+00:00","url":"https://junglewise.ai/threats/cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer"},{"cve":"CVE-2026-42266","cvss":8.8,"epss":0.0085,"slug":"cve-2026-42266-project-jupyter-jupyterlab-privilege-escalation-in-pypi-extension","title":"Project Jupyter JupyterLab privilege escalation in PyPI Extension Manager","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:47.017+00:00","url":"https://junglewise.ai/threats/cve-2026-42266-project-jupyter-jupyterlab-privilege-escalation-in-pypi-extension"},{"cve":"CVE-2024-39700","cvss":3.1,"epss":0.0109,"slug":"cve-2024-39700-pysec-2024-322-jupyterlab-extension-template-is-a-copier-template","title":"PYSEC-2024-322 - JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option","severity":"low","exploited":false,"published_at":"2024-07-16T18:15:07.857+00:00","url":"https://junglewise.ai/threats/cve-2024-39700-pysec-2024-322-jupyterlab-extension-template-is-a-copier-template"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"jupyterlab (PyPI)","slug":"pypi-jupyterlab","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://jupyter.org","repo_url":"https://github.com/jupyterlab/jupyterlab","description":"Web-based interactive computing environment for notebooks, code, and data.","url":"https://junglewise.ai/threats/technologies/pypi-jupyterlab"},"most_severe":[{"cve":"CVE-2026-42557","cvss":9.6,"epss":0.0072,"slug":"cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer","title":"Jupyter JupyterLab arbitrary command execution via HTML sanitizer bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T16:16:48.167+00:00","url":"https://junglewise.ai/threats/cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer"},{"cve":"CVE-2026-42266","cvss":8.8,"epss":0.0085,"slug":"cve-2026-42266-project-jupyter-jupyterlab-privilege-escalation-in-pypi-extension","title":"Project Jupyter JupyterLab privilege escalation in PyPI Extension Manager","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:47.017+00:00","url":"https://junglewise.ai/threats/cve-2026-42266-project-jupyter-jupyterlab-privilege-escalation-in-pypi-extension"},{"cve":"CVE-2026-73417","cvss":4,"epss":0.0075,"slug":"cve-2026-73417-jupyterlab-arbitrary-code-execution-via-malicious-overrides-json","title":"JupyterLab arbitrary code execution via malicious overrides.json","severity":"medium","exploited":false,"published_at":"2026-08-13T22:17:26.133+00:00","url":"https://junglewise.ai/threats/cve-2026-73417-jupyterlab-arbitrary-code-execution-via-malicious-overrides-json"},{"cve":"CVE-2026-73415","cvss":4,"epss":0.0074,"slug":"cve-2026-73415-jupyterlab-image-viewer-allows-xss-when-opening-malicious-image","title":"PYSEC-2026-3671 - JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab","severity":"medium","exploited":false,"published_at":"2026-08-19T11:56:25.364725+00:00","url":"https://junglewise.ai/threats/cve-2026-73415-jupyterlab-image-viewer-allows-xss-when-opening-malicious-image"},{"cve":"CVE-2026-73416","cvss":4,"epss":0.0066,"slug":"cve-2026-73416-jupyterlab-extension-blocklist-bypass-via-package-name-variant","title":"JupyterLab extension blocklist bypass via package name variant","severity":"medium","exploited":false,"published_at":"2026-08-13T22:17:25.963+00:00","url":"https://junglewise.ai/threats/cve-2026-73416-jupyterlab-extension-blocklist-bypass-via-package-name-variant"},{"cve":"CVE-2026-40171","cvss":4,"epss":0.0066,"slug":"cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss","title":"PYSEC-2026-2682 - Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","severity":"medium","exploited":false,"published_at":"2026-07-13T15:02:55.67876+00:00","url":"https://junglewise.ai/threats/cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss"},{"cve":"CVE-2025-59842","cvss":4,"epss":0.0024,"slug":"cve-2025-59842-jupyterlab-latex-typesetter-links-did-not-enforce-noopener","title":"PYSEC-2026-1482 - JupyterLab LaTeX typesetter links did not enforce `noopener` attribute","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:05.847517+00:00","url":"https://junglewise.ai/threats/cve-2025-59842-jupyterlab-latex-typesetter-links-did-not-enforce-noopener"},{"cve":"CVE-2021-32797","cvss":3.1,"epss":0.0266,"slug":"cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action","title":"PYSEC-2026-688 - JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:10.480332+00:00","url":"https://junglewise.ai/threats/cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action"},{"cve":"CVE-2024-39700","cvss":3.1,"epss":0.0109,"slug":"cve-2024-39700-pysec-2024-322-jupyterlab-extension-template-is-a-copier-template","title":"PYSEC-2024-322 - JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option","severity":"low","exploited":false,"published_at":"2024-07-16T18:15:07.857+00:00","url":"https://junglewise.ai/threats/cve-2024-39700-pysec-2024-322-jupyterlab-extension-template-is-a-copier-template"},{"cve":"CVE-2024-22421","cvss":3.1,"epss":0.0067,"slug":"cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens","title":"PYSEC-2026-2534 - JupyterLab vulnerable to potential authentication and CSRF tokens leak","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.685378+00:00","url":"https://junglewise.ai/threats/cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}