Plugin Manager Lock-Rule Bypass in JupyterLab by Project Jupyter
CVE-2026-73627

6MEDIUM

Key Information:

Vendor

Jupyterlab

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73627?

JupyterLab versions 4.1.0 to 4.5.9 and 4.6.0 to 4.6.1 are susceptible to a vulnerability that allows authenticated users to bypass administrator lock rules. This is achieved through direct requests to the /lab/api/plugins endpoint, enabling the activation or deactivation of locked plugins, as well as child plugins of multi-plugin extensions. Such bypassing can compromise data integrity and violate any hardening measures or restrictions that rely on locked plugins. Users are advised to upgrade to versions 4.6.2 or 4.5.10 to mitigate this issue.

Affected Version(s)

jupyterlab 0

jupyterlab 0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
MUFFANUJ
krassowski
.