Cross-Site Scripting Vulnerability in Dask Distributed by Dask
CVE-2026-23528
5.3MEDIUM
What is CVE-2026-23528?
A security issue in Dask Distributed prior to version 2026.1.0 allows for cross-site scripting (XSS) attacks. When used in conjunction with Jupyter Lab and jupyter-server-proxy, attackers can create malicious URLs that exploit weaknesses in the Dask dashboard. If users inadvertently click on these crafted links while their Jupyter Lab is running, it can trigger unintended code execution on the default Jupyter Python kernel. This vulnerability highlights the importance of keeping software updated and being cautious with link sharing.
Affected Version(s)
distributed < 2026.1.0
