jupyterlab is vulnerable to Race Condition (TOCTOU)
42
Medium Risk
Clicking a command link button in a Markdown file or notebook output opens a Trust prompt naming the command, and choosing Trust marks the current document as trusted. markdownviewer:trust and notebook:trust read whichever document is current when the user answers the prompt, not when they clicked, so if another document becomes current while the prompt is open, that document is the one marked trusted instead. An untrusted document that becomes current during that window then has every command link button run without a further prompt. The fix binds the trust decision to the document that was current when the prompt opened.
You are affected if you are using a version that falls within the vulnerable range and a second document becomes the active one while a command link Trust prompt is open, for example from a workspace restoring at startup or an extension activating a widget.
jupyterlab is vulnerable to Race Condition (TOCTOU) in versions 4.5.7 - 4.5.10 and 4.6.0 - 4.6.3.
Upgrade the jupyterlab library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.