CVE-2026-42266

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*

History

26 May 2026, 18:33

Type Values Removed Values Added
References () https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7 - () https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7 - Patch, Release Notes
References () https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4 - () https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-37w4-hwhx-4rc4 - Mitigation, Vendor Advisory
References () https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html - () https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html - Product
References () https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations - () https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations - Product
First Time Jupyter
Jupyter jupyterlab
CPE cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*

21 May 2026, 02:16

Type Values Removed Values Added
References
  • () https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.7 -
  • () https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html -
  • () https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations -
Summary (en) jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. (en) JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

13 May 2026, 16:32

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 16:16

Updated : 2026-05-26 18:33


NVD link : CVE-2026-42266

Mitre link : CVE-2026-42266

CVE.ORG link : CVE-2026-42266


JSON object : View

Products Affected

jupyter

  • jupyterlab
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CWE-602

Client-Side Enforcement of Server-Side Security