VendorsJupyterjupyterlaball versions
Vulnerabilities

Jupyter Jupyterlab

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-39700
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
Published 2024-07-16 · Analyzed
9.9EPSS 0.010
CVE-2021-32797
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Published 2021-08-09 · Modified
9.6EPSS 0.027
CVE-2026-42557
jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content
Published 2026-05-13 · Modified
9.6EPSS 0.004
CVE-2026-42266
JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
Published 2026-05-13 · Modified
8.8EPSS 0.006
CVE-2024-22421
Potential authentication and CSRF tokens leak in JupyterLab
Published 2024-01-19 · Modified
7.6EPSS 0.007
CVE-2024-43805
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
Published 2024-08-28 · Analyzed
7.6EPSS 0.004
CVE-2024-22420
Stored cross site scripting in Markdown Preview in JupyterLab
Published 2024-01-19 · Modified
6.5EPSS 0.006
CVE-2025-59842
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Published 2025-09-26 · Analyzed
4.3EPSS 0.002