{"id":"CVE-2026-67338","aliases":["GHSA-vmhf-c436-hxj4"],"url":"https://o3.security/vulnerability/CVE-2026-67338","summary":"JupyterLab before 4.5.9 Stored XSS via Extension Manager","details":"JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.","published":"2026-08-01T12:22:17.437Z","modified":"2026-08-12T03:51:22.628039313Z","cvss":null,"epss":{"score":0.00172,"percentile":0.06783,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"jupyterlab","fixedVersion":"4.5.9"}],"fix":{"url":"https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6","label":"jupyterlab/jupyterlab@4e61e07"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67338.json"},{"type":"ADVISORY","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67338"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/jupyterlab-before-stored-xss-via-extension-manager"},{"type":"FIX","url":"https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6"},{"type":"FIX","url":"https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.628039313Z"}}