REDHAT-BUG-2477086: High severity jupyter JupyterLab vulnerability
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
jupyterlabto a version that resolves this vulnerability.Fixed in 4.5.7
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2477086?
The severity of REDHAT-BUG-2477086 is high, rated at 7.
How do I fix REDHAT-BUG-2477086?
To fix REDHAT-BUG-2477086, update JupyterLab to version 4.5.7 or later.
What are the risks associated with REDHAT-BUG-2477086?
The risks associated with REDHAT-BUG-2477086 include potential security vulnerabilities due to improper sanitization of HTML content.
Which software is affected by REDHAT-BUG-2477086?
REDHAT-BUG-2477086 affects JupyterLab, a component of the Jupyter Notebook Architecture.
When was REDHAT-BUG-2477086 published?
REDHAT-BUG-2477086 was published on May 13, 2026.