Cross-Site Scripting Vulnerability in JupyterLab ImageViewer
CVE-2026-73415

7.5HIGH

Key Information:

Vendor

Jupyterlab

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73415?

The JupyterLab ImageViewer component exhibits a vulnerability related to how SVG images are handled. An improperly revoked blob URL can allow an SVG to retain an executable same-origin context when accessed through the viewer. This leads to cross-site scripting, enabling attackers to execute arbitrary code on the JupyterLab server. This vulnerability has been addressed in JupyterLab versions 4.5.10 and 4.6.2. Users are encouraged to upgrade to these versions or later to mitigate potential risks.

Affected Version(s)

jupyterlab < 4.5.10 < 4.5.10

jupyterlab >= 4.6.0, < 4.6.2 < 4.6.0, 4.6.2

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.