Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67338

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

A flaw was found in JupyterLab. The Extension Manager fails to validate URI protocols in package metadata URLs. This allows attackers to publish malicious PyPI packages containing javascript: URLs in their project metadata. When a user clicks on the extension name, arbitrary JavaScript code can be executed within the JupyterLab environment, potentially leading to information disclosure or unauthorized actions.

Отчет

This Moderate impact flaw in JupyterLab's Extension Manager allows for stored cross-site scripting. Malicious PyPI packages with crafted metadata URLs can execute arbitrary JavaScript within the JupyterLab environment when a user interacts with the extension name. This primarily affects Red Hat OpenShift AI and other deployments utilizing JupyterLab where users have access to and interact with the Extension Manager.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch210-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cpu-torch291-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch210-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-cuda130-torch291-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-th06-rocm64-torch291-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2509997jupyterlab: JupyterLab: Stored cross-site scripting in Extension Manager allows arbitrary code execution

EPSS

Процентиль: 7%
0.00172
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 месяца назад

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

CVSS3: 6.1
nvd
около 1 месяца назад

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

CVSS3: 6.1
debian
около 1 месяца назад

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...

CVSS3: 6.1
github
около 1 месяца назад

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

EPSS

Процентиль: 7%
0.00172
Низкий

6.1 Medium

CVSS3