CVE-2026-102831: JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JupyterLabto a version that resolves this vulnerability.Fixed in 4.5.11 - Upgrade
Upgrade
JupyterLabto a version that resolves this vulnerability.Fixed in 4.6.4 - Upgrade
Upgrade
Notebookto a version that resolves this vulnerability.Fixed in 7.6.3 - Upgrade
Upgrade
JupyterLite Coreto a version that resolves this vulnerability.Fixed in 0.8.4
Event History
Frequently Asked Questions
What conditions are required for exploitation?
An attacker must persuade a user to paste attacker-controlled code-cell JSON from the system clipboard. The JupyterLab setting useSystemClipboardForCells must be active and pasteCodeCellsWithoutOutput must be disabled; user interaction is required, but the pasted cell does not need to be executed.
Which pasted cell types are affected?
Only code cells are affected. Markdown and raw cells are not affected because their output is sanitized.
What is the impact after a successful paste?
The pasted code cell can retain metadata.trusted, causing HTML output to bypass sanitization and execute script in the authenticated JupyterLab origin. This can compromise confidentiality and integrity in that origin.
What can be done before updating?
Disable useSystemClipboardForCells or enable pasteCodeCellsWithoutOutput to prevent the vulnerable paste path from accepting trusted output. Avoid pasting untrusted code cells from the system clipboard.
Which releases contain fixes?
Fixed releases are JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.