CVE-2026-42266

Name
CVE-2026-42266
Description
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4
security-advisories@github.com https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7
security-advisories@github.com https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html
security-advisories@github.com https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-42266
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2477072
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42266.json

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:* jupyterlab >= 4.0.0 < 4.5.7

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jupyterlab edge-community 4.5.6-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.6-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.6-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.4-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.3-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.2-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.1-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.10-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.9-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.7-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.6-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.5-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.5-r0 fossdd <fossdd@pwned.life> possibly vulnerable
jupyterlab 3.23-community 4.5.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable