Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gx64-gj6p-pc4c | JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2. | |
| Title | jupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T20:54:14.775Z
Reserved: 2026-08-12T14:32:11.795Z
Link: CVE-2026-73415
Updated: 2026-08-12T20:35:39.545Z
Status : Received
Published: 2026-08-12T20:17:56.660
Modified: 2026-08-12T21:17:40.770
Link: CVE-2026-73415
No data.
OpenCVE Enrichment
No data.
Github GHSA