jupyterlab is vulnerable to Code Injection
68
Medium Risk
JupyterLab turns a language pack's Plural-Forms header into a function with new Function, and the regular expression that validates the header is anchored only at the start. A header that begins with a valid plural rule can carry arbitrary trailing text, which runs as JavaScript in the JupyterLab page once that language pack is selected and a plural string is translated. The fix anchors the validation regex at the end so trailing content after the plural rule is rejected.
You are affected if you are using a version that falls within the vulnerable range and a language pack you did not write is installed and selected so its translation catalogue is loaded.
jupyterlab is vulnerable to Code Injection in versions 3.0.0 - 4.5.10 and 4.6.0 - 4.6.3.
Upgrade the jupyterlab library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.