Hi,
The following vulnerability was published for jupyterlab.
CVE-2026-73417[0]:
| jupyterlab is an extensible environment for interactive and
| reproducible computing, based on the Jupyter Notebook Architecture.
| From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook
| settings to be shared and applied through an overrides.json file
| using the Import button in the Settings Editor. In
| packages/notebook-extension/schema/tracker.json and
| packages/notebook-extension/src/index.ts, the
| sideBySideLeftMarginOverride and sideBySideRightMarginOverride
| settings are not properly validated before being inserted into style
| content, allowing a crafted settings file to contain instructions
| that execute as code instead of only changing display preferences. A
| user can import the malicious file, or an attacker with access to a
| shared settings location can plant an overrides.json that is applied
| automatically. The embedded code runs with the affected user's
| access and can read or modify notebooks and files and run code
| through the notebook server, including on a connected kernel. This
| issue is fixed in versions 4.5.10 and 4.6.2.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-73417
https://www.cve.org/CVERecord?id=CVE-2026-73417
[1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
[2] https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore