JupyterLab Extensible Environment Vulnerability in Extension Manager
CVE-2026-73416

6.1MEDIUM

Key Information:

Vendor

Jupyterlab

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73416?

The vulnerability in JupyterLab's PyPI extension manager allows an authenticated user to bypass restrictions on installing certain extensions. Despite being on the blocklist, an attacker can exploit the extension manager's weak package-name normalization process to request installation of disallowed packages. The issue exists in versions 4.5.0 through 4.5.10 and 4.6.2, and can potentially lead to integrity breaches and service availability issues. The vulnerability has been addressed in subsequent updates, specifically in versions 4.5.10 and 4.6.2.

Affected Version(s)

jupyterlab >= 4.5.0, < 4.5.10 < 4.5.0, 4.5.10

jupyterlab >= 4.6.0, < 4.6.2 < 4.6.0, 4.6.2

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.