Skip to content
JupyterGHSA-gx64-gj6p-pc4c

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

HighCVE-2026-73415 · Published Jul 22, 2026 · updated Sep 10, 2026

JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ### Impact This vulnerability allows for arbitrary code execution. ### Patches JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch. ### Workarounds Disable the image viewer plugin: ``` jupyter labextension disable @jupyterlab/imageviewer-extension:plugin ``` Confirm with: ``` jupyter labextension list ```

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterlab
PyPI
>= 4.6.0, < 4.6.24.6.2
< 4.5.104.5.10
Details and references

More Jupyter advisories

All Jupyter
Advisory
Jupyter: code execution
Medium6.1Jul 23
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
HighJul 22
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
MediumJul 22
JupyterLab PluginManager lock-rule enforcement bypass
MediumJul 22
Jupyter: improper access control
Low0.0Jul 22
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Medium6.8Jul 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.