Cross-Site Scripting Vulnerability in Dask Distributed by Dask
CVE-2026-23528

5.3MEDIUM

Key Information:

Vendor

Dask

Vendor
CVE Published:
16 January 2026

What is CVE-2026-23528?

A security issue in Dask Distributed prior to version 2026.1.0 allows for cross-site scripting (XSS) attacks. When used in conjunction with Jupyter Lab and jupyter-server-proxy, attackers can create malicious URLs that exploit weaknesses in the Dask dashboard. If users inadvertently click on these crafted links while their Jupyter Lab is running, it can trigger unintended code execution on the default Jupyter Python kernel. This vulnerability highlights the importance of keeping software updated and being cautious with link sharing.

Affected Version(s)

distributed < 2026.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.