High-Severity XSS Flaw Found in JupyterLab Image Viewer, Patch Now Available
A stored Cross-Site Scripting vulnerability (CVSS 8.2) has been disclosed in JupyterLab's Image Viewer component, tracked as GHSA-GX64-GJ6P-PC4C and published on July 22, 2026. The flaw allows attackers to embed malicious JavaScript inside SVG files, which executes within a victim's active session when the image is opened in a new browser tab. Exploitation can lead to arbitrary remote command execution and potential host takeover, with a proof-of-concept already available. Affected versions include JupyterLab 4.6.0 up to 4.6.2 and certain earlier 4.5.x releases, with fixes delivered in versions 4.5.10 and 4.6.2. Users are advised to upgrade immediately via pip or conda, enforce a Content Security Policy, and restrict raw SVG uploads in shared multi-user environments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in