THREAT OPS › Threat News › [NVD] CVE-2026-67338 (MEDIUM 6.1) — JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary Java
[NVD] CVE-2026-67338 (MEDIUM 6.1) — JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary Java
CVE-2026-67338 CVSS: 6.1 MEDIUM Published: 2026-08-01T13:17:04.843
JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-67338cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67338