Improper Encoding or Escaping of Output Affecting jupyterlab package, versions [3.3.0, 4.5.10)[4.6.0a0, 4.6.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-JUPYTERLAB-18233306
  • published23 Jul 2026
  • disclosed22 Jul 2026
  • creditUnknown

Introduced: 22 Jul 2026

New CVE NOT AVAILABLE CWE-116  (opens in a new tab)
CWE-79  (opens in a new tab)

How to fix?

Upgrade jupyterlab to version 4.5.10, 4.6.2 or higher.

Overview

jupyterlab is a JupyterLab computational environment.

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the import of a crafted overrides.json settings file. An attacker can execute arbitrary code with the privileges of the affected user by convincing the user to import a malicious settings file or by placing such a file in a directory that is automatically loaded by the application. This can lead to unauthorized access or modification of user files and execution of code on the user's behalf.

Note: This is only exploitable if the attacker can write to a directory from which the application loads settings, or if the user imports a malicious settings file.

CVSS Base Scores

version 4.0
version 3.1