Source: jupyterlab Version: 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for jupyterlab. CVE-2026-73417[0]: | jupyterlab is an extensible environment for interactive and | reproducible computing, based on the Jupyter Notebook Architecture. | From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook | settings to be shared and applied through an overrides.json file | using the Import button in the Settings Editor. In | packages/notebook-extension/schema/tracker.json and | packages/notebook-extension/src/index.ts, the | sideBySideLeftMarginOverride and sideBySideRightMarginOverride | settings are not properly validated before being inserted into style | content, allowing a crafted settings file to contain instructions | that execute as code instead of only changing display preferences. A | user can import the malicious file, or an attacker with access to a | shared settings location can plant an overrides.json that is applied | automatically. The embedded code runs with the affected user's | access and can read or modify notebooks and files and run code | through the notebook server, including on a connected kernel. This | issue is fixed in versions 4.5.10 and 4.6.2. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73417 https://www.cve.org/CVERecord?id=CVE-2026-73417 [1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj [2] https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c Please adjust the affected versions in the BTS as needed. Regards, Salvatore

