Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4. | |
| Title | JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T20:00:25.547Z
Reserved: 2026-09-29T17:25:25.265Z
Link: CVE-2026-102830
Updated: 2026-09-29T20:00:17.309Z
Status : Received
Published: 2026-09-29T19:17:25.527
Modified: 2026-09-29T20:17:17.923
Link: CVE-2026-102830
No data.
OpenCVE Enrichment
No data.