{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/jupyterlab-4.6.0-through-4.6.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JupyterLab (prior to 4.5.10)","JupyterLab (4.6.0 through 4.6.1)"],"_cs_severities":["high"],"_cs_tags":["xss","rce","vulnerability","jupyterlab","web"],"_cs_type":"advisory","_cs_vendors":["Jupyter"],"content_html":"\u003cp\u003eJupyterLab, an interactive development environment, contains a cross-site scripting (XSS) vulnerability within its image viewer component. This flaw allows an attacker to achieve remote code execution (RCE) on the JupyterLab server. The vulnerability is triggered when a specially crafted malicious image file is opened via the image viewer, and subsequently, the user opens this image in a new browser tab. Successful exploitation could lead to arbitrary code execution on the server hosting JupyterLab. The affected versions include JupyterLab prior to \u003ccode\u003e4.5.10\u003c/code\u003e and versions \u003ccode\u003e4.6.0\u003c/code\u003e up to, but not including, \u003ccode\u003e4.6.2\u003c/code\u003e. Patches are available in versions \u003ccode\u003e4.5.10\u003c/code\u003e and \u003ccode\u003e4.6.2\u003c/code\u003e. This is a high-severity issue because it transitions an XSS to RCE, providing a significant foothold for attackers.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eCraft Malicious Image\u003c/strong\u003e: An attacker crafts a specially designed image file containing embedded XSS payload.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeliver Image\u003c/strong\u003e: The malicious image is delivered to a target user, often through social engineering or by being placed in a location accessible to the JupyterLab user.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser Opens Image in JupyterLab Viewer\u003c/strong\u003e: The user interacts with the malicious image by opening it within the JupyterLab image viewer.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUser Opens Image in New Tab\u003c/strong\u003e: The user then, as part of their workflow, opts to open the image from the viewer into a new browser tab.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eXSS Execution\u003c/strong\u003e: The malicious payload within the image is executed in the user's browser context due to the XSS vulnerability in the image viewer's new tab rendering.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRemote Code Execution\u003c/strong\u003e: The executed XSS payload leverages the user's JupyterLab session privileges to perform actions, potentially leading to arbitrary command execution on the underlying JupyterLab server.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistent Access/Data Exfiltration\u003c/strong\u003e: With RCE, the attacker can establish persistence, exfiltrate sensitive data from the JupyterLab environment or the host server, or further compromise the system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in arbitrary code execution on the JupyterLab server. This grants attackers the ability to execute commands, potentially access or exfiltrate sensitive data, establish persistence within the environment, and further compromise the host system. Given that JupyterLab is often used for data science and development, this could expose intellectual property, sensitive research data, or grant access to development environments. The vulnerability affects any organization utilizing unpatched JupyterLab instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch JupyterLab to \u003ccode\u003ev4.6.2\u003c/code\u003e or \u003ccode\u003ev4.5.10\u003c/code\u003e immediately by upgrading your \u003ccode\u003epip/jupyterlab\u003c/code\u003e installation to remediate the vulnerability.\u003c/li\u003e\n\u003cli\u003eAs a workaround if immediate patching is not possible, disable the image viewer plugin using the command \u003ccode\u003ejupyter labextension disable @jupyterlab/imageviewer-extension:plugin\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor JupyterLab server process creation logs and network connection logs for unusual activity that might indicate compromise, especially after user interactions with untrusted image files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T23:15:38Z","date_published":"2026-07-22T23:15:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-jupyterlab-image-viewer-xss/","summary":"A cross-site scripting (XSS) vulnerability exists in JupyterLab's image viewer, allowing an attacker to achieve remote code execution (RCE) on the JupyterLab server if a specially crafted image file is opened in the image viewer and then opened in a new browser tab; affected versions include JupyterLab prior to 4.5.10 and versions from 4.6.0 up to, but not including, 4.6.2, with patches available in versions 4.5.10 and 4.6.2.","title":"JupyterLab Image Viewer XSS Vulnerability Leading to RCE","url":"https://feed.craftedsignal.io/briefs/2026-07-jupyterlab-image-viewer-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - JupyterLab (4.6.0 Through 4.6.1)","version":"https://jsonfeed.org/version/1.1"}