Showing 1 vulnerability on this page for help-extension

Signals CISA KEV Ransomware Nuclei
jupyterlab vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker

In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click. An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate contr

CWE-601CWE-79May 6, 2026
CVSS8.4v4.0EPSS0.476%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX