JupyterLab Extensible Environment Vulnerability in Extension Manager
CVE-2026-73416
6.1MEDIUM
What is CVE-2026-73416?
The vulnerability in JupyterLab's PyPI extension manager allows an authenticated user to bypass restrictions on installing certain extensions. Despite being on the blocklist, an attacker can exploit the extension manager's weak package-name normalization process to request installation of disallowed packages. The issue exists in versions 4.5.0 through 4.5.10 and 4.6.2, and can potentially lead to integrity breaches and service availability issues. The vulnerability has been addressed in subsequent updates, specifically in versions 4.5.10 and 4.6.2.
Affected Version(s)
jupyterlab >= 4.5.0, < 4.5.10 < 4.5.0, 4.5.10
jupyterlab >= 4.6.0, < 4.6.2 < 4.6.0, 4.6.2
