MODERATEPyPI

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol

CVE-2026-67338Published 1 month agoUpdated 3 days agoSource: OSV

Affected packages

  • jupyterlabbefore 4.5.9

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.18%
EPSS percentile
7.1%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 7%.

JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol | HackTribune