jupyterlab Vulnerabilities and Affected Products
Vulnerabilities associated with help-extension.
Products
Clear product- jupyterlab14 vulnerabilities
- jupyterlab-git3 vulnerabilities
- extension-template1 vulnerability
- help-extension1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-40171HIGH | Jupyter Notebook and JupyterLab token theft via stored XSS in help command linkerIn Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click. An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate contr… | CVSS8.4v4.0 | EPSS0.476% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |