Skip to content
JupyterGHSA-h5v5-8746-g7mm

JupyterLab PluginManager lock-rule enforcement bypass

MediumPublished Jul 22, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterlab
PyPI
>= 4.6.0, < 4.6.24.6.2
>= 4.1.0, < 4.5.104.5.10
Details and references

JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`. ### Impact Users could workaround the plugin manager lock rules via direct API access for either: - child plugins of extensions covering multiple plugins - when "lock all" was issued by the administrator The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms. ### Patches JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch. Users of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too. ### Workarounds Manually lock all plugins that should be locked. The core plugin identifiers can be found in [the documentation](https://jupyterlab.readthedocs.io/en/latest/extension/extension_points.html#core-plugins) and identifiers for all installed extensions are listed in the [Plugin Manager](https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#managing-plugins-with-plugin-manager).

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-602, CWE-863

More Jupyter advisories

All Jupyter
DateAdvisory
Jul 22JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
CVE-2026-73626Low0.0fixed in 4.5.10, 4.6.2
Jul 22JupyterLab: PyPI extension blocklist package-name canonicalization bypass
CVE-2026-73416Mediumfixed in 4.5.10, 4.6.2
Jul 22JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
CVE-2026-73415Highfixed in 4.5.10, 4.6.2
Jul 22JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2026-73417Highfixed in 4.5.10, 4.6.2
Jul 23jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
CVE-2026-6657Medium6.1no fix yet
Jul 13Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2026-5422Medium6.8fixed in 2.18.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.