CVE-2026-102831: JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard

Published Sep 29, 2026
·
Updated

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.

Affected Software

3 affected components
jupyter JupyterLab>=4.5.0<4.5.11, >=4.6.0<4.6.4
jupyter notebook>=7.5.0<7.6.3
jupyter JupyterLite Core>=0.7.0<0.8.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade JupyterLab to a version that resolves this vulnerability.

    Fixed in 4.5.11
  2. Upgrade

    Upgrade JupyterLab to a version that resolves this vulnerability.

    Fixed in 4.6.4
  3. Upgrade

    Upgrade Notebook to a version that resolves this vulnerability.

    Fixed in 7.6.3
  4. Upgrade

    Upgrade JupyterLite Core to a version that resolves this vulnerability.

    Fixed in 0.8.4

Event History

Sep 29, 2026
CVE Published
via MITRE·06:58 PM
Data Sourced
via MITRE·06:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for exploitation?

An attacker must persuade a user to paste attacker-controlled code-cell JSON from the system clipboard. The JupyterLab setting useSystemClipboardForCells must be active and pasteCodeCellsWithoutOutput must be disabled; user interaction is required, but the pasted cell does not need to be executed.

2

Which pasted cell types are affected?

Only code cells are affected. Markdown and raw cells are not affected because their output is sanitized.

3

What is the impact after a successful paste?

The pasted code cell can retain metadata.trusted, causing HTML output to bypass sanitization and execute script in the authenticated JupyterLab origin. This can compromise confidentiality and integrity in that origin.

4

What can be done before updating?

Disable useSystemClipboardForCells or enable pasteCodeCellsWithoutOutput to prevent the vulnerable paste path from accepting trusted output. Avoid pasting untrusted code cells from the system clipboard.

5

Which releases contain fixes?

Fixed releases are JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203