Improper Access Control Affecting jupyterlab package, versions *


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.36% (28th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-JUPYTERLAB-18767483
  • published14 Aug 2026
  • disclosed13 Aug 2026

Introduced: 13 Aug 2026

CVE-2026-73626  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

There is no fixed version for Debian:13 jupyterlab.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jupyterlab package and not the jupyterlab package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.

CVSS Base Scores

version 3.1