jupyterlab is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
The JupyterLab Extension Manager renders a package's home-page link from PyPI project metadata without validating the URI protocol. A package published with a javascript: URL in its metadata is copied into the frontend link and stored, so viewing the extension listing and clicking the extension name runs the embedded script in the JupyterLab origin. This stored cross-site scripting can be escalated to code execution through the notebook server and connected kernels. The fix validates and neutralizes non-safe URI protocols before the link is rendered.
You are affected if you run an affected jupyterlab version with the Extension Manager enabled against the default PyPI source, and you open the extension listing and click the name of an untrusted package whose PyPI project metadata carries a javascript: home-page URL.
jupyterlab is vulnerable to Cross-Site Scripting (XSS) in versions 0.34.0 - 4.5.8.
Upgrade the jupyterlab library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant