JavaScript Injection Flaw in JupyterLab Affecting Multiple Versions
CVE-2026-102830
What is CVE-2026-102830?
A JavaScript injection vulnerability exists in JupyterLab and JupyterLite Core whereby a specially crafted Plural-Forms header in third-party language packs can append malicious JavaScript to a valid plural rule. This flaw occurs due to insufficient validation of the header, allowing potentially harmful code to be executed in the context of authenticated JupyterLab sessions. Although this risk is primarily prevalent in specific Jupyter Server environments, where authenticated APIs may be exploited to read, modify files, and execute additional code, it is less significant in JupyterLite, which typically does not expose such extensive server functionalities. The issue has been addressed in JupyterLab versions 4.5.11 and 4.6.4 and in JupyterLite Core version 0.8.4.
Affected Version(s)
jupyterlab >= 3.0.0, < 4.5.11 < 3.0.0, 4.5.11
jupyterlab >= 4.6.0, < 4.6.4 < 4.6.0, 4.6.4
jupyterlite-core < 0.8.4
