Source: jupyterlab Version: 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-6 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for jupyterlab. CVE-2026-102830[0]: | JupyterLab is an extensible environment for interactive and | reproducible computing, based on the Jupyter Notebook Architecture. | From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite | Core 0.8.3 and earlier, the Plural-Forms header in a selected third- | party language pack can append JavaScript after a valid plural rule | because prefix-only regular-expression validation accepts a matching | prefix without requiring the entire header to match. JupyterLab | passes the accepted expression to new Function, so loading the | catalogue and translating a plural string executes the appended code | in the authenticated JupyterLab origin. Where Jupyter Server | kernels, terminals, and APIs are exposed, the code can use | authenticated server APIs to read or modify files and run code. | Impact is much more limited in JupyterLite because it typically | lacks most exposed Jupyter Server surfaces. The default English | locale is unaffected because it does not load a translation | catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and | JupyterLite Core 0.8.4. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102830 https://www.cve.org/CVERecord?id=CVE-2026-102830 [1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
