<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>JupyterLab (4.5.0-4.6.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/jupyterlab-4.5.0-4.6.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:22:09 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/jupyterlab-4.5.0-4.6.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>JupyterLab Cross-Site Scripting via System Clipboard</title><link>https://feed.craftedsignal.io/briefs/2026-10-jupyterlab-xss/</link><pubDate>Thu, 01 Oct 2026 20:22:09 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-jupyterlab-xss/</guid><description>JupyterLab is vulnerable to a cross-site scripting (XSS) attack via the system clipboard that allows unauthorized JavaScript execution within the user's session when pasting cells from an external source.</description><content:encoded><![CDATA[<p>JupyterLab versions 4.5.0 through 4.6.3 contain a security vulnerability (CVE-2026-102831) that enables cross-site scripting (XSS) via the system clipboard. The vulnerability exists in the paste mechanism, which parses clipboard text as JSON for cell data. Crucially, the application fails to strip the <code>metadata.trusted</code> field from imported cell content. An attacker can supply a malicious JSON payload in the system clipboard that labels a cell's output as trusted. Because JupyterLab does not sanitize trusted output, any embedded <code>&lt;script&gt;</code> elements are executed within the JupyterLab origin.</p>
<p>The attack is highly impactful as it executes arbitrary JavaScript in the context of an authenticated user's active session. This allows for unauthorized interaction with the Jupyter Server REST API, enabling actions such as reading or writing files within the server root, spawning kernels, or interacting with terminals. Exploitation does not require prior access to the target system, only that a user pastes content into a vulnerable JupyterLab instance while the attacker-controlled payload resides in the clipboard.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker hosts a webpage containing malicious code designed to populate a user's system clipboard upon interaction (e.g., clicking a button).</li>
<li>The attacker-controlled clipboard content is populated with a crafted JSON array representing a Jupyter notebook cell, containing <code>{&quot;metadata&quot;: { &quot;trusted&quot;: true }}</code> and a malicious <code>&lt;script&gt;</code> payload within the output field.</li>
<li>The victim visits the malicious webpage and interacts with it, granting the page access to write to the system clipboard.</li>
<li>The victim switches to an active, authenticated JupyterLab session in their browser.</li>
<li>The victim performs a paste action (via menu, palette, or shortcut) while the malicious payload is in the system clipboard.</li>
<li>JupyterLab parses the JSON, respects the <code>metadata.trusted</code> flag, and renders the untrusted output.</li>
<li>The browser executes the attacker's JavaScript within the JupyterLab origin.</li>
<li>The malicious script makes unauthorized requests to the Jupyter Server REST API to exfiltrate files or execute arbitrary commands.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full session compromise within the Jupyter environment. An attacker can read, modify, or delete any file accessible to the Jupyter process, execute arbitrary commands via kernel interaction, or gain shell access if terminals are enabled. Affected products include JupyterLab, Jupyter Notebook 7.5.0-7.6.2, and JupyterLite 0.7.0-0.8.3. This vulnerability significantly impacts research and development environments where JupyterLab is deployed to process sensitive data or credentials.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade JupyterLab to version 4.6.4 or 4.5.11 immediately.</li>
<li>For applications bundling JupyterLab, such as Notebook v7+, upgrade the underlying <code>jupyterlab</code> package to a patched version.</li>
<li>If immediate upgrading is not possible, set <code>@jupyterlab/notebook-extension:tracker:useSystemClipboardForCells</code> to <code>false</code> in the settings to disable system clipboard pasting for cells.</li>
<li>As an additional mitigation, set <code>@jupyterlab/notebook-extension:tracker:pasteCodeCellsWithoutOutput</code> to <code>true</code> to ensure pasted cells do not contain the vulnerable output fields.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>