Clipboard Vulnerability in JupyterLab Affects Multiple Versions
CVE-2026-102831
8.1HIGH
What is CVE-2026-102831?
A vulnerability in JupyterLab allows for the acceptance of attacker-controlled JSON via the system clipboard when certain features are enabled. This can result in untrusted HTML output being marked as trusted, enabling scripts to execute in the JupyterLab environment without direct user interaction. This issue affects multiple versions and is resolved in the latest updates.
Affected Version(s)
jupyterlab >= 4.5.0, < 4.5.11 < 4.5.0, 4.5.11
jupyterlab >= 4.6.0, < 4.6.4 < 4.6.0, 4.6.4
jupyterlite-core >= 0.7.0, < 0.8.4
