No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10. | |
| Title | JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager | |
| First Time appeared |
Jupyter
Jupyter jupyterlab |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jupyter
Jupyter jupyterlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T12:57:46.464Z
Reserved: 2026-08-13T11:17:25.160Z
Link: CVE-2026-73626
Updated: 2026-08-13T12:57:41.554Z
Status : Received
Published: 2026-08-13T12:17:27.897
Modified: 2026-08-13T13:19:21.833
Link: CVE-2026-73626
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:15:04Z