CRITICAL9.8CVE-2024-39700Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action from 0, < 4.3.0
CRITICAL9.6CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content from 0, < 4.5.7
CRITICAL9.6CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content from 0, < 4.5.7
HIGH7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
from 0, < 3.6.8
HIGH7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
from 0, < 3.6.8, >= 4.0.0, < 4.2.5
HIGH7.6Potential authentication and CSRF tokens leak in JupyterLab
>= 4.0.0, < 4.0.11
HIGH7.6Potential authentication and CSRF tokens leak in JupyterLab
from 0, < 3.6.7, >= 4.0.0, < 4.0.11
HIGH7.4JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
from 0, < 1.2.21
MEDIUM6.5Stored cross site scripting in Markdown Preview in JupyterLab
>= 4.0.0, < 4.0.11
MEDIUM6.5Stored cross site scripting in Markdown Preview in JupyterLab
>= 4.0.0, < 4.0.11
—Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
from 0, < 4.5.7
—Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
from 0, < 4.5.7