← Vulnerability feed

Vulnerability record · CVE-2026-42266 · published 13 May 2026

CVE-2026-42266: Jupyterlab argument injection vulnerability

Jupyter · Jupyterlab

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

8.8 CVSS 3.1 High EPSS 0.85% · top 43.4% CWE-88 · Argument injectionCWE-602 · CWE-602
8.8CVSS 3.1 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References
28 Aug 2026Last modified by NVD

Description

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-42266 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39700Jupyterlab code injection vulnerabilityJupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `…EPSS 1.1%9.6CVE-2021-32797Jupyterlab cross-site scripting vulnerabilityJupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted noteboo…EPSS 2.7%8.6CVE-2026-42557Jupyterlab cross-site scripting vulnerabilityjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, Jupyt…EPSS 0.72%6.5CVE-2024-22421Jupyterlab relative path traversal vulnerabilityJupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterL…EPSS 0.67%6.1CVE-2024-43805Jupyterlab cross-site scripting vulnerabilityjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability de…EPSS 0.40%6.1CVE-2024-22420Jupyterlab cross-site scripting vulnerabilityJupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerabilit…EPSS 0.57%2.1CVE-2025-59842Jupyterlab vulnerabilityjupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.…EPSS 0.24%9.2CVE-2026-86060MikroTik RouterOS SSH login argument injection privilege escalationRouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altere…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2026-42266), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.