JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
Medium6.8CVE-2026-102830 · Published Oct 1, 2026
## Description A language pack ships a `Plural-Forms` header saying how the language counts, for example `nplurals=2; plural=(n != 1);`. JupyterLab turns that string into a function with `new Function`, so the header gets executed. The check that meant to keep it safe was a regular expression. The regex was anchored at the start but not at the end, so it accepted any string that began with a valid plural rule and ignored everything after it. A header such as the following passed the check, and the part after the plural rule ran in the JupyterLab page as soon as the first plural string was translated: ``` nplurals=2; plural=(n > 1); <anything here ran as JavaScript> ``` Users are affected if all of the following are true: - they run JupyterLab 3.0.0 through 4.6.3, or an application that bundles it such as Notebook 7; - a language pack they did not write is installed in the environment; and - that language is selected, so its catalogue is loaded An installation using the default English locale loads no catalogue and is not affected. > CVE assignment pending, GitHub CNA is experiencing severe backlog ### Impact The code in the header ran in the JupyterLab page, in the same or...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| jupyterlab PyPI | >= 4.6.0, < 4.6.4 | 4.6.4 |
| >= 3.0.0, < 4.5.11 | 4.5.11 |
Details and references
## Description A language pack ships a `Plural-Forms` header saying how the language counts, for example `nplurals=2; plural=(n != 1);`. JupyterLab turns that string into a function with `new Function`, so the header gets executed. The check that meant to keep it safe was a regular expression. The regex was anchored at the start but not at the end, so it accepted any string that began with a valid plural rule and ignored everything after it. A header such as the following passed the check, and the part after the plural rule ran in the JupyterLab page as soon as the first plural string was translated: ``` nplurals=2; plural=(n > 1); <anything here ran as JavaScript> ``` Users are affected if all of the following are true: - they run JupyterLab 3.0.0 through 4.6.3, or an application that bundles it such as Notebook 7; - a language pack they did not write is installed in the environment; and - that language is selected, so its catalogue is loaded An installation using the default English locale loads no catalogue and is not affected. > CVE assignment pending, GitHub CNA is experiencing severe backlog ### Impact The code in the header ran in the JupyterLab page, in the same origin and session as the authenticated user. It could call the Jupyter Server REST API as that user: read and write any file under the server root, start a kernel and run code in it, and open a terminal where terminals are enabled. Nothing had to be clicked; translating one plural string was enough, and that happens during normal use of the interface. What this changes is who has to be trusted. A language pack is a Python package, and installing one is already a privileged act, so an attacker who can get any package installed has server-side code execution regardless of this issue. The header is different because it is catalogue metadata: it travels with translation content, through the [translation pipeline](https://jupyterlab.readthedocs.io/en/latest/developer/internationalization.html) that carries strings from Crowdin into the language packs, and it is reviewed as text rather than as code. Anyone able to change a catalogue, or to publish a pack under a name someone installs, got JavaScript execution in every browser that selected that language. Note: the impact is much more limited on JupyterLite which typically does not have access to most of the surfaces that this flaw exposes. ### Patches JupyterLab [`v4.6.4`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4) and [`v4.5.11`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11) contain the patch. The check now has to match the whole header, so a plural rule followed by anything else is rejected and no function is built from it. JupyterLab 3.x reached end of life and receives no patch. Its users should move to a supported 4.x release. Users of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too. ### Workarounds Use the English locale, which loads no catalogue: ```bash jupyter lab --LabApp.default_locale=en ``` or the following traitlet: ```python c.LabApp.default_locale = 'en' ``` Everyone then sees the interface in English, whatever language they had selected. To check what is installed instead of switching, report any pack whose header carries more than a plural rule: ```bash python -c " import re from jupyterlab_server.translation_utils import get_language_packs, get_language_pack ok = re.compile(r'\s*nplurals\s*=\s*\d+\s*;\s*plural\s*=[\s\-?|&=!<>+*/%:;n0-9_()]+') packs, _ = get_language_packs() for locale in packs: data, _ = get_language_pack(locale) for domain, catalog in (data or {}).items(): header = catalog.get('', {}).get('plural_forms') if header and not ok.fullmatch(header): print('SUSPECT', locale, domain, repr(header)) " ``` The command prints nothing when every catalogue is sound. A line of output names the pack to remove.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-625, CWE-79, CWE-94
- Also known as
- CVE-2026-102830, PYSEC-2026-4056, PYSEC-2026-4059
- github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj
- nvd.nist.gov/vuln/detail/CVE-2026-102830
- github.com/jupyterlab/jupyterlab/commit/985a3223cd77fd4f991cd90066342a90711d70f6
- github.com/jupyterlab/jupyterlab/commit/de324ae91346c713c4f5e5485f97b6e914e0f774
- github.com/jupyterlab/jupyterlab/commit/f9de43dc565a1118120d466117f877a189a4ce90
- github.com/jupyterlab/jupyterlab
- github.com/jupyterlab/jupyterlab/releases/tag/v4.5.11
- github.com/jupyterlab/jupyterlab/releases/tag/v4.6.4
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Jupyter: information disclosure in errors | Medium5.4 | 4.5.11+1 more |
| Oct 1 | JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard | High8.1 | 4.5.11+2 more |
| Sep 17 | Jupyter Server: 5xx request logging leaks token-bearing Referer header values | High7.1 | 2.21.0 |
| Aug 25 | JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login | Medium5.3 | 5.5.0 |
| Jul 23 | Jupyter: code execution | Medium6.1 | No fix yet |
| Jul 22 | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) | High | 4.5.10+1 more |