JupyterLab Cross-Site Scripting via System Clipboard
JupyterLab is vulnerable to a cross-site scripting (XSS) attack via the system clipboard that allows unauthorized JavaScript execution within the user's session when pasting cells from an external source.
CVE search metadata
CVE search record: CVE-2026-102831. Severity: high. CVSS: 8.1. EPSS: 0.20%. KEV: no. Product: JupyterLab (4.5.0-4.6.3), Notebook (7.5.0-7.6.2), JupyterLite (0.7.0-0.8.3), JupyterLite Core (0.7.0-0.8.3). Brief: JupyterLab Cross-Site Scripting via System Clipboard. Brief link: https://feed.craftedsignal.io/briefs/2026-10-jupyterlab-xss/
JupyterLab versions 4.5.0 through 4.6.3 contain a security vulnerability (CVE-2026-102831) that enables cross-site scripting (XSS) via the system clipboard. The vulnerability exists in the paste mechanism, which parses clipboard text as JSON for cell data. Crucially, the application fails to strip the metadata.trusted field from imported cell content. An attacker can supply a malicious JSON payload in the system clipboard that labels a cell's output as trusted. Because JupyterLab does not sanitize trusted output, any embedded <script> elements are executed within the JupyterLab origin.
The attack is highly impactful as it executes arbitrary JavaScript in the context of an authenticated user's active session. This allows for unauthorized interaction with the Jupyter Server REST API, enabling actions such as reading or writing files within the server root, spawning kernels, or interacting with terminals. Exploitation does not require prior access to the target system, only that a user pastes content into a vulnerable JupyterLab instance while the attacker-controlled payload resides in the clipboard.
Attack Chain
- Attacker hosts a webpage containing malicious code designed to populate a user's system clipboard upon interaction (e.g., clicking a button).
- The attacker-controlled clipboard content is populated with a crafted JSON array representing a Jupyter notebook cell, containing
{"metadata": { "trusted": true }}and a malicious<script>payload within the output field. - The victim visits the malicious webpage and interacts with it, granting the page access to write to the system clipboard.
- The victim switches to an active, authenticated JupyterLab session in their browser.
- The victim performs a paste action (via menu, palette, or shortcut) while the malicious payload is in the system clipboard.
- JupyterLab parses the JSON, respects the
metadata.trustedflag, and renders the untrusted output. - The browser executes the attacker's JavaScript within the JupyterLab origin.
- The malicious script makes unauthorized requests to the Jupyter Server REST API to exfiltrate files or execute arbitrary commands.
Impact
Successful exploitation results in full session compromise within the Jupyter environment. An attacker can read, modify, or delete any file accessible to the Jupyter process, execute arbitrary commands via kernel interaction, or gain shell access if terminals are enabled. Affected products include JupyterLab, Jupyter Notebook 7.5.0-7.6.2, and JupyterLite 0.7.0-0.8.3. This vulnerability significantly impacts research and development environments where JupyterLab is deployed to process sensitive data or credentials.
Recommendation
- Upgrade JupyterLab to version 4.6.4 or 4.5.11 immediately.
- For applications bundling JupyterLab, such as Notebook v7+, upgrade the underlying
jupyterlabpackage to a patched version. - If immediate upgrading is not possible, set
@jupyterlab/notebook-extension:tracker:useSystemClipboardForCellstofalsein the settings to disable system clipboard pasting for cells. - As an additional mitigation, set
@jupyterlab/notebook-extension:tracker:pasteCodeCellsWithoutOutputtotrueto ensure pasted cells do not contain the vulnerable output fields.
Immediate actions
Patch JupyterLab to v4.6.4 or v4.5.11 across all development and production environments
Mitigations
Disable system clipboard for JupyterLab cells via configuration settings
CVE-2026-102831