VDB

CVE-2026-73627

CVE-2026-73627 PUBLISHED CVSS 6 MEDIUM

Reported by VulnCheck · Published August 13, 2026

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked — including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.

Risk Scores

CVSS 4.0
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
jupyterlabjupyterlab0
jupyterlabjupyterlab0
jupyterlabjupyterlab0, 0, 0
jupyterjupyterlab

Timeline

  • Aug 13, 2026 Coalition ESS Score
  • Aug 13, 2026 CVE Published
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 9, 2026 CVE Updated
  • Sep 12, 2026 EPSS Score
  • Sep 17, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›