CVE-2026-67338CWE-84

CVE-2026-67338

Medium · published August 1, 2026

CVSS v3.1
6.1
EPSS
0%
Percentile
6.8
In the wild
Unconfirmed
What it is

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00172 · 6.8th percentile
Weakness
CWE-84 · Improper Neutralization of Encoded URI Schemes in a Web Page
Published
2026-08-01T17:17Z
References (4)
EPSS history
Timeline
  • 01 AUG 12:22Z
    JupyterLab before 4.5.9 Stored XSS via Extension Manager
    cvelistv5