Source: jupyterlab
Version: 4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for jupyterlab.

CVE-2026-73417[0]:
| jupyterlab is an extensible environment for interactive and
| reproducible computing, based on the Jupyter Notebook Architecture.
| From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook
| settings to be shared and applied through an overrides.json file
| using the Import button in the Settings Editor. In
| packages/notebook-extension/schema/tracker.json and
| packages/notebook-extension/src/index.ts, the
| sideBySideLeftMarginOverride and sideBySideRightMarginOverride
| settings are not properly validated before being inserted into style
| content, allowing a crafted settings file to contain instructions
| that execute as code instead of only changing display preferences. A
| user can import the malicious file, or an attacker with access to a
| shared settings location can plant an overrides.json that is applied
| automatically. The embedded code runs with the affected user's
| access and can read or modify notebooks and files and run code
| through the notebook server, including on a connected kernel. This
| issue is fixed in versions 4.5.10 and 4.6.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-73417
    https://www.cve.org/CVERecord?id=CVE-2026-73417
[1] 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
[2] 
https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to