Skip to content
JupyterPYSEC-2024-322

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template

Critical9.8CVE-2024-39700 · Published Jul 16, 2024 · updated Jul 13, 2026

Source advisory

Affected versions

PackageAffectedFixed in
jupyterlab
PyPI
< 4.3.04.3.0
Details and references

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the `main` branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
the CVSS score
Also known as
BIT-jupyterlab-2024-39700, CVE-2024-39700, GHSA-45gq-v5wm-82wg

More Jupyter advisories

All Jupyter
DateAdvisory
Aug 82024JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
CVE-2024-41942High7.2fixed in 4.1.6, 5.1.0
Jun 62024Jupyter server on Windows discloses Windows user password hash
CVE-2024-35178High7.5fixed in 2.14.1
Aug 292024HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-43805High7.6fixed in 3.6.8, 4.2.5, 7.2.2
Mar 282024Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
CVE-2024-28233High8.1fixed in 4.1.0
Jan 192024JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2024-22421High7.6fixed in 3.6.7, 4.0.11, 7.0.7
Jan 192024JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-22420Medium6.5fixed in 4.0.11, 7.0.7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.