Intel

AIKIDO-2026-240789

jupyterlab is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)GHSA-jwrc-gm9j-263p Published 5 days ago

42

Medium Risk

This Affects:

PYTHONjupyterlab
4.5.7 - 4.5.10
Fixed in 4.5.11
4.6.0 - 4.6.3
Fixed in 4.6.4
Are you affected? Scan for Free

TL;DR

Clicking a command link button in a Markdown file or notebook output opens a Trust prompt naming the command, and choosing Trust marks the current document as trusted. markdownviewer:trust and notebook:trust read whichever document is current when the user answers the prompt, not when they clicked, so if another document becomes current while the prompt is open, that document is the one marked trusted instead. An untrusted document that becomes current during that window then has every command link button run without a further prompt. The fix binds the trust decision to the document that was current when the prompt opened.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a second document becomes the active one while a command link Trust prompt is open, for example from a workspace restoring at startup or an extension activating a widget.

Background info

jupyterlab is vulnerable to Race Condition (TOCTOU) in versions 4.5.7 - 4.5.10 and 4.6.0 - 4.6.3.

How to fix this

Upgrade the jupyterlab library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform