Hi,
The following vulnerability was published for jupyterlab.
CVE-2026-102904[0]:
| JupyterLab is an extensible environment for interactive and
| reproducible computing, based on the Jupyter Notebook Architecture.
| From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension
| Manager uninstall request reaches ExtensionHandler.post, which
| validates extension names for installation but passes uninstall
| names to PyPIExtensionManager.uninstall and python -m pip uninstall
| without rejecting option-like values. The security impact requires
| that the PyPI Extension Manager is enabled, the account can call the
| extension API, and kernels and terminals are disabled or delegated
| to remote hosts; otherwise the user can already read files and make
| outbound requests directly. An authenticated user with extension API
| access can supply a pip requirements option to make the server read
| a local file or fetch an internal URL, and reflected parse errors
| can return the first unparsable line or response content. A pip log
| option can also create or corrupt a chosen path with pip-generated
| log text, but the requester cannot select an arbitrary disclosed
| line or arbitrary file content, and the injection does not add code
| execution or availability impact beyond ordinary package removal.
| This issue is fixed in JupyterLab 4.5.11 and 4.6.4.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-102904
https://www.cve.org/CVERecord?id=CVE-2026-102904
[1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3325-v43h-43rv
[2] https://github.com/jupyterlab/jupyterlab/commit/e277bc958e737130ac47b6c5078d08b29298828f
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore