JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template
Critical9.8CVE-2024-39700 · Published Jul 16, 2024 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| jupyterlab PyPI | < 4.3.0 | 4.3.0 |
Details and references
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the `main` branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the CVSS score
- Also known as
- BIT-jupyterlab-2024-39700, CVE-2024-39700, GHSA-45gq-v5wm-82wg
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 82024 | JupyterHub has a privilege escalation vulnerability with the `admin:users` scope CVE-2024-41942High7.2fixed in 4.1.6, 5.1.0 | High7.2 | 4.1.6, 5.1.0 |
| Jun 62024 | Jupyter server on Windows discloses Windows user password hash CVE-2024-35178High7.5fixed in 2.14.1 | High7.5 | 2.14.1 |
| Aug 292024 | HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering CVE-2024-43805High7.6fixed in 3.6.8, 4.2.5, 7.2.2 | High7.6 | 3.6.8, 4.2.5, 7.2.2 |
| Mar 282024 | Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing CVE-2024-28233High8.1fixed in 4.1.0 | High8.1 | 4.1.0 |
| Jan 192024 | JupyterLab vulnerable to potential authentication and CSRF tokens leak CVE-2024-22421High7.6fixed in 3.6.7, 4.0.11, 7.0.7 | High7.6 | 3.6.7, 4.0.11, 7.0.7 |
| Jan 192024 | JupyterLab vulnerable to SXSS in Markdown Preview CVE-2024-22420Medium6.5fixed in 4.0.11, 7.0.7 | Medium6.5 | 4.0.11, 7.0.7 |