VDB

CVE-2026-73626

CVE-2026-73626 PUBLISHED CVSS 7.7 HIGH

Reported by VulnCheck · Published August 13, 2026

JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.

Risk Scores

CVSS 4.0
7.7
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
jupyterlabjupyterlab4.6.0, 4.6.1
jupyterlabjupyterlab0, 4.5.10
jupyterjupyterlab4.6.0, 0, 4.6.0
jupyterlabjupyterlab4.6.0, 4.6.1, 0

Timeline

  • Aug 13, 2026 Coalition ESS Score
  • Aug 13, 2026 CVE Published
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 29, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
  • Sep 24, 2026 EPSS Score
  • Sep 26, 2026 EPSS Score
  • Sep 30, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›