CVE-2026-42266 Details
Description
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
A vulnerability exists in JupyterLab versions 4.0.0 prior to 4.5.6, where the allow-list for extensions that can be installed from the PyPI Extension Manager is not properly enforced. This flaw allows packages from outside the default PyPI index to be installed, potentially undermining security measures in multi-tenant deployments or environments with restricted package installation.
Users should update JupyterLab to version 4.5.7, which includes the necessary patch. For applications that depend on JupyterLab, such as Notebook v7+, the 'jupyterlab' package should also be updated. As an additional step, users can switch to a read-only extension manager to prevent unauthorized installations.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | redhat-SADP |
| CWE-88 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| jupyter jupyterlab | >= 4.0.0, < 4.5.7 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | CVE Modified | redhat-SADP |
| Aug 28, 2026 | CVE Modified | [email protected] |
| Jul 22, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 6, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | New CVE Received | [email protected] |