#1149998 jupyterlab: CVE-2026-102830

Package:
src:jupyterlab
Source:
src:jupyterlab
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 05:25:03 UTC
Severity:
normal
Tags:
#1149998#5
Date:
2026-10-05 05:23:56 UTC
From:
To:
Hi,

The following vulnerability was published for jupyterlab.

CVE-2026-102830[0]:
| JupyterLab is an extensible environment for interactive and
| reproducible computing, based on the Jupyter Notebook Architecture.
| From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite
| Core 0.8.3 and earlier, the Plural-Forms header in a selected third-
| party language pack can append JavaScript after a valid plural rule
| because prefix-only regular-expression validation accepts a matching
| prefix without requiring the entire header to match. JupyterLab
| passes the accepted expression to new Function, so loading the
| catalogue and translating a plural string executes the appended code
| in the authenticated JupyterLab origin. Where Jupyter Server
| kernels, terminals, and APIs are exposed, the code can use
| authenticated server APIs to read or modify files and run code.
| Impact is much more limited in JupyterLite because it typically
| lacks most exposed Jupyter Server surfaces. The default English
| locale is unaffected because it does not load a translation
| catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and
| JupyterLite Core 0.8.4.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-102830
https://www.cve.org/CVERecord?id=CVE-2026-102830
[1] https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore