CVE-2026-73627
Reported by VulnCheck · Published August 13, 2026
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked — including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| jupyterlab | jupyterlab | 0 |
| jupyterlab | jupyterlab | 0 |
| jupyterlab | jupyterlab | 0, 0, 0 |
| jupyter | jupyterlab |
Timeline
- Aug 13, 2026 Coalition ESS Score
- Aug 13, 2026 CVE Published
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 9, 2026 CVE Updated
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-h5v5-8746-g7mm) vendor-advisory
- VulnCheck Advisory: JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass third-party-advisory