CRITICAL9.6CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content
from 0, < 4.5.7
HIGH8.8CVE-2026-42266JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
>= 4.0.0, < 4.5.7
HIGH7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
from 0, < 4.2.5
HIGH7.6Potential authentication and CSRF tokens leak in JupyterLab
from 0, < 3.6.7, >= 4.0.0, < 4.0.11
MEDIUM6.5Stored cross site scripting in Markdown Preview in JupyterLab
>= 4.0.0, < 4.2.4
—Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
from 0, < 4.5.7
—JupyterLab LaTeX typesetter links did not enforce `noopener` attribute