CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-gx64-gj6p-pc4c: JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

high
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. Impact This vulnerability allows for arbitrary code execution. Patches JupyterLab v4.6.2 and v4.5.10 contain the patch. Workarounds Disable the image viewer plugin: jupyter labextension disable @jupyterlab/imageviewer-extension:plugin Confirm with: jupyter labextension list

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high
Published
2026-07-22
Last updated
2026-07-22
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-gx64-gj6p-pc4c

More from GitHub Security Advisories