CVE-2026-42557

Name
CVE-2026-42557
Description
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-mqcg-5x36-vfcg
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://access.redhat.com/security/cve/CVE-2026-42557
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://bugzilla.redhat.com/show_bug.cgi?id=2477086
0b0ca135-0b70-47e7-9f44-1890c2a1c46c https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42557.json

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:* jupyterlab >= None < 4.5.7
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:* notebook >= 7.0.0 < 7.5.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
jupyterlab edge-community 4.5.6-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.6-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.6-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.4-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.3-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.2-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.1-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.5.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.10-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.9-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.7-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.6-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.5-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyterlab edge-community 4.4.5-r0 fossdd <fossdd@pwned.life> possibly vulnerable
jupyterlab 3.23-community 4.5.0-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
jupyter-notebook edge-community 7.5.6-r0 Achill Gilgenast <achill@achill.org> fixed
jupyter-notebook 3.24-community 7.5.6-r0 Achill Gilgenast <achill@achill.org> fixed