{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/notebook-7.5.0-7.6.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-102831"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["JupyterLab (4.5.0-4.6.3)","Notebook (7.5.0-7.6.2)","JupyterLite (0.7.0-0.8.3)","JupyterLite Core (0.7.0-0.8.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Jupyter"],"content_html":"\u003cp\u003eJupyterLab versions 4.5.0 through 4.6.3 contain a security vulnerability (CVE-2026-102831) that enables cross-site scripting (XSS) via the system clipboard. The vulnerability exists in the paste mechanism, which parses clipboard text as JSON for cell data. Crucially, the application fails to strip the \u003ccode\u003emetadata.trusted\u003c/code\u003e field from imported cell content. An attacker can supply a malicious JSON payload in the system clipboard that labels a cell's output as trusted. Because JupyterLab does not sanitize trusted output, any embedded \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e elements are executed within the JupyterLab origin.\u003c/p\u003e\n\u003cp\u003eThe attack is highly impactful as it executes arbitrary JavaScript in the context of an authenticated user's active session. This allows for unauthorized interaction with the Jupyter Server REST API, enabling actions such as reading or writing files within the server root, spawning kernels, or interacting with terminals. Exploitation does not require prior access to the target system, only that a user pastes content into a vulnerable JupyterLab instance while the attacker-controlled payload resides in the clipboard.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker hosts a webpage containing malicious code designed to populate a user's system clipboard upon interaction (e.g., clicking a button).\u003c/li\u003e\n\u003cli\u003eThe attacker-controlled clipboard content is populated with a crafted JSON array representing a Jupyter notebook cell, containing \u003ccode\u003e{\u0026quot;metadata\u0026quot;: { \u0026quot;trusted\u0026quot;: true }}\u003c/code\u003e and a malicious \u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e payload within the output field.\u003c/li\u003e\n\u003cli\u003eThe victim visits the malicious webpage and interacts with it, granting the page access to write to the system clipboard.\u003c/li\u003e\n\u003cli\u003eThe victim switches to an active, authenticated JupyterLab session in their browser.\u003c/li\u003e\n\u003cli\u003eThe victim performs a paste action (via menu, palette, or shortcut) while the malicious payload is in the system clipboard.\u003c/li\u003e\n\u003cli\u003eJupyterLab parses the JSON, respects the \u003ccode\u003emetadata.trusted\u003c/code\u003e flag, and renders the untrusted output.\u003c/li\u003e\n\u003cli\u003eThe browser executes the attacker's JavaScript within the JupyterLab origin.\u003c/li\u003e\n\u003cli\u003eThe malicious script makes unauthorized requests to the Jupyter Server REST API to exfiltrate files or execute arbitrary commands.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full session compromise within the Jupyter environment. An attacker can read, modify, or delete any file accessible to the Jupyter process, execute arbitrary commands via kernel interaction, or gain shell access if terminals are enabled. Affected products include JupyterLab, Jupyter Notebook 7.5.0-7.6.2, and JupyterLite 0.7.0-0.8.3. This vulnerability significantly impacts research and development environments where JupyterLab is deployed to process sensitive data or credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade JupyterLab to version 4.6.4 or 4.5.11 immediately.\u003c/li\u003e\n\u003cli\u003eFor applications bundling JupyterLab, such as Notebook v7+, upgrade the underlying \u003ccode\u003ejupyterlab\u003c/code\u003e package to a patched version.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrading is not possible, set \u003ccode\u003e@jupyterlab/notebook-extension:tracker:useSystemClipboardForCells\u003c/code\u003e to \u003ccode\u003efalse\u003c/code\u003e in the settings to disable system clipboard pasting for cells.\u003c/li\u003e\n\u003cli\u003eAs an additional mitigation, set \u003ccode\u003e@jupyterlab/notebook-extension:tracker:pasteCodeCellsWithoutOutput\u003c/code\u003e to \u003ccode\u003etrue\u003c/code\u003e to ensure pasted cells do not contain the vulnerable output fields.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T20:22:09Z","date_published":"2026-10-01T20:22:09Z","id":"https://feed.craftedsignal.io/briefs/2026-10-jupyterlab-xss/","summary":"JupyterLab is vulnerable to a cross-site scripting (XSS) attack via the system clipboard that allows unauthorized JavaScript execution within the user's session when pasting cells from an external source.","title":"JupyterLab Cross-Site Scripting via System Clipboard","url":"https://feed.craftedsignal.io/briefs/2026-10-jupyterlab-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Notebook (7.5.0-7.6.2)","version":"https://jsonfeed.org/version/1.1"}