VYPR

rpm package

opensuse/python-jupyterlab&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/python-jupyterlab&distro=openSUSE%20Tumbleweed

Vulnerabilities (9)

  • CVE-2026-73417HigAug 13, 2026
    affected < 4.5.10-1.1fixed 4.5.10-1.1

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button i

  • CVE-2026-73416MedAug 13, 2026
    affected < 4.5.10-1.1fixed 4.5.10-1.1

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, JupyterLab's PyPI extension manager enforces b

  • CVE-2026-73627MedAug 13, 2026
    affected < 4.5.10-1.1fixed 4.5.10-1.1

    JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/

  • CVE-2026-73626HigAug 13, 2026
    affected < 4.5.10-1.1fixed 4.5.10-1.1

    JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct cal

  • CVE-2026-73415HigAug 12, 2026
    affected < 4.5.10-1.1fixed 4.5.10-1.1

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image an

  • CVE-2026-42557CriMay 13, 2026
    affected < 4.5.7-1.1fixed 4.5.7-1.1

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker li

  • CVE-2026-42266HigMay 13, 2026
    affected < 4.5.7-1.1fixed 4.5.7-1.1

    JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced

  • CVE-2026-40171HigMay 6, 2026
    affected < 4.5.7-1.1fixed 4.5.7-1.1

    In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be ch

  • CVE-2025-59842MedSep 26, 2025
    affected < 4.4.9-1.1fixed 4.4.9-1.1

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include t