github.com
https://github.com/jupyterlab/jupyterlab CVE-2024-22420
MEDIUM
Stored cross site scripting in Markdown Preview in JupyterLab
Record summary
CVE-2024-22420 has a selected CVSS score of 6.5 (medium).
Description
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab version 4.0.11 has been patched. Users are advised to upgrade. Users unable to upgrade should disable the table of contents extension.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
jupyterlabBrowse jupyterlab / jupyterlab | CVE List | >=4.0.0, < 4.0.11 | affected |
jupyterlabBrowse PyPI / jupyterlab | GitHub Advisory | 4.0.0 to < 4.0.11 · Fixed in 4.0.11 | affected |
notebookBrowse PyPI / notebook | GitHub Advisory | 7.0.0 to < 7.0.7 · Fixed in 7.0.7 | affected |
References
6github.com
https://github.com/jupyterlab/jupyterlab/commit/dda0033cd49449572d077bbecd33b18d8d05f48a github.com
https://github.com/jupyterlab/jupyterlab/commit/e1b3aabab603878e46add445a3114e838411d2df github.comConfirmation
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-4m77-cmpx-vjc4 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UQJKNRDRFMKGVRIYNNN6CKMNJDNYWO2H nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-22420