Source: jupyterlab Version: 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-6 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for jupyterlab. CVE-2026-102904[0]: | JupyterLab is an extensible environment for interactive and | reproducible computing, based on the Jupyter Notebook Architecture. | From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension | Manager uninstall request reaches ExtensionHandler.post, which | validates extension names for installation but passes uninstall | names to PyPIExtensionManager.uninstall and python -m pip uninstall | without rejecting option-like values. The security impact requires | that the PyPI Extension Manager is enabled, the account can call the | extension API, and kernels and terminals are disabled or delegated | to remote hosts; otherwise the user can already read files and make | outbound requests directly. An authenticated user with extension API | access can supply a pip requirements option to make the server read | a local file or fetch an internal URL, and reflected parse errors | can return the first unparsable line or response content. A pip log | option can also create or corrupt a chosen path with pip-generated | log text, but the requester cannot select an arbitrary disclosed | line or arbitrary file content, and the injection does not add code | execution or availability impact beyond ordinary package removal. | This issue is fixed in JupyterLab 4.5.11 and 4.6.4. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-102904 https://www.cve.org/CVERecord?id=CVE-2026-102904 [1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv [2] https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f Please adjust the affected versions in the BTS as needed. Regards, Salvatore -- Pkg-javascript-devel mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel
