VDB
KO
HIGH

GHSA-gx64-gj6p-pc4c

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

Quick fix

GHSA-gx64-gj6p-pc4c — jupyterlab: upgrade to the fixed version with the command below.

pip install --upgrade 'jupyterlab>=4.6.2'

Details

JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server.

### Impact

This vulnerability allows for arbitrary code execution.

### Patches

JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch.

### Workarounds

Disable the image viewer plugin:

``` jupyter labextension disable @jupyterlab/imageviewer-extension:plugin ```

Confirm with:

``` jupyter labextension list ```

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / jupyterlab
Introduced in: 4.6.0 Fixed in: 4.6.2
Fix pip install --upgrade 'jupyterlab>=4.6.2'
PyPI / jupyterlab
Introduced in: 0 Fixed in: 4.5.10
Fix pip install --upgrade 'jupyterlab>=4.5.10'

References