Client-Side Enforcement of Server-Side Security Affecting jupyterlab package, versions <4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.42% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN14-JUPYTERLAB-18767485
  • published14 Aug 2026
  • disclosed13 Aug 2026

Introduced: 13 Aug 2026

CVE-2026-73627  (opens in a new tab)
CWE-602  (opens in a new tab)

How to fix?

Upgrade Debian:14 jupyterlab to version 4.4.10+ds1+3.1.0+0.16.6+~cs1.4.4-4 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jupyterlab package and not the jupyterlab package as distributed by Debian. See How to fix? for Debian:14 relevant fixed versions and status.

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked — including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.