Intel

AIKIDO-2026-198906

jupyterlab is vulnerable to Code Injection

Code InjectionGHSA-3jqq-pw4j-pqcj Published 5 days ago

68

Medium Risk

This Affects:

PYTHONjupyterlab
3.0.0 - 4.5.10
Fixed in 4.5.11
4.6.0 - 4.6.3
Fixed in 4.6.4
Are you affected? Scan for Free

TL;DR

JupyterLab turns a language pack's Plural-Forms header into a function with new Function, and the regular expression that validates the header is anchored only at the start. A header that begins with a valid plural rule can carry arbitrary trailing text, which runs as JavaScript in the JupyterLab page once that language pack is selected and a plural string is translated. The fix anchors the validation regex at the end so trailing content after the plural rule is rejected.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a language pack you did not write is installed and selected so its translation catalogue is loaded.

Background info

jupyterlab is vulnerable to Code Injection in versions 3.0.0 - 4.5.10 and 4.6.0 - 4.6.3.

How to fix this

Upgrade the jupyterlab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform