JupyterLab Vulnerability in PyPI Extension Manager Uninstall Process
CVE-2026-102904
5.4MEDIUM
What is CVE-2026-102904?
This vulnerability in JupyterLab allows an authenticated user with access to the extension API to exploit the PyPI Extension Manager's uninstall functionality. The flaw occurs due to improper validation of input values, enabling the user to potentially manipulate pip commands to read local files or fetch internal URLs. While this can result in reflected parsing errors or modified logs, the injection does not facilitate arbitrary code execution, limiting the overall impact to the uninstallation of packages only. The issue has been rectified in versions 4.5.11 and 4.6.4.
Affected Version(s)
jupyterlab >= 4.0.0, < 4.5.11 < 4.0.0, 4.5.11
jupyterlab >= 4.6.0, < 4.6.4 < 4.6.0, 4.6.4
