Cross-Site Scripting Vulnerability in JupyterLab ImageViewer
CVE-2026-73415
7.5HIGH
What is CVE-2026-73415?
The JupyterLab ImageViewer component exhibits a vulnerability related to how SVG images are handled. An improperly revoked blob URL can allow an SVG to retain an executable same-origin context when accessed through the viewer. This leads to cross-site scripting, enabling attackers to execute arbitrary code on the JupyterLab server. This vulnerability has been addressed in JupyterLab versions 4.5.10 and 4.6.2. Users are encouraged to upgrade to these versions or later to mitigate potential risks.
Affected Version(s)
jupyterlab < 4.5.10 < 4.5.10
jupyterlab >= 4.6.0, < 4.6.2 < 4.6.0, 4.6.2
