Plugin Manager Lock-Rule Bypass in JupyterLab by Project Jupyter
CVE-2026-73627
6MEDIUM
What is CVE-2026-73627?
JupyterLab versions 4.1.0 to 4.5.9 and 4.6.0 to 4.6.1 are susceptible to a vulnerability that allows authenticated users to bypass administrator lock rules. This is achieved through direct requests to the /lab/api/plugins endpoint, enabling the activation or deactivation of locked plugins, as well as child plugins of multi-plugin extensions. Such bypassing can compromise data integrity and violate any hardening measures or restrictions that rely on locked plugins. Users are advised to upgrade to versions 4.6.2 or 4.5.10 to mitigate this issue.
Affected Version(s)
jupyterlab 0
jupyterlab 0
