CVE-2026-42266: JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowedextensionsuris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.
Other sources
The allow-list of extensions that can be installed from PyPI Extension Manager (allowedextensionsuris) is not correctly enforced by JupyterLab prior to 4.5.X. The PyPI Extension Manager was not contained to packages listed on the default PyPI index.
This has security implications for deployments that: - have allow-listed specific extensions with aim to prevent users from installing packages - have the kernel and terminals disabled or delegated to remote hosts (thus no access to install packages in the single-user server environment) - have multi-tenant deployments that is not configured for untrusted users (as per documented on JupyterHub https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html) - have the (default) PyPI Extension Manger enabled
Impact
An authenticated attacker - such as a student in a shared JupyterHub environment or a user in a multi-tenant JupyterLab deployment - can escalate their privileges. This might allow for data exfiltration, lateral movement within the network, and persistent compromise of the server infrastructure.
Patches
JupyterLab v4.5.7 contains the patch.
Users of applications that depend on JupyterLab, such as Notebook v7+, should update jupyterlab package too.
Workarounds
Switch to read-only extension manager by adding the following command line option:
bash --LabApp.extensionmanager=readonly
or the following traitlet:
python c.LabApp.extensionmanager = 'readonly'
You can confirm that the read-only manager is in use from GUI:
<img width="293" height="293" alt="image" src="https://github.com/user-attachments/assets/8016c809-633e-4ed0-a5bc-6bc4793caa0f" />
Note: configuration of a PyPI proxy with allow-listed packages is not sufficient to protect from this vulnerability.
Resources
- allow-list https://jupyterlab.readthedocs.io/en/stable/user/extensions.html#listing-configuration - https://jupyterhub.readthedocs.io/en/5.2.1/explanation/websecurity.html - https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#extension-manager-implementations
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/jupyterlabto a version that resolves this vulnerability.Fixed in 4.5.7 - Upgrade
Upgrade
jupyterlabto a version that resolves this vulnerability.Fixed in 4.5.7 - Configuration
Switch the PyPI Extension Manager to read-only mode by setting the command-line option / traitlet to c.LabApp.extension_manager = 'readonly' (as described in the material). Confirm in the GUI that the read-only manager is in use.
JupyterLab (LabApp extension manager) LabApp.extension_manager = readonly
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42266?
CVE-2026-42266 has security implications due to improper enforcement of the allowed extensions list in JupyterLab.
How do I fix CVE-2026-42266?
To fix CVE-2026-42266, update JupyterLab to version 4.5.7 or later.
What versions of JupyterLab are affected by CVE-2026-42266?
JupyterLab versions between 4.0.0 and 4.5.6 are affected by CVE-2026-42266.
What are the implications of CVE-2026-42266 for JupyterLab users?
The implications of CVE-2026-42266 include potential security risks related to the installation of unverified extensions from PyPI.
How can I verify if my JupyterLab installation is affected by CVE-2026-42266?
You can verify if your JupyterLab installation is affected by checking the installed version against the vulnerable range of versions.