CVE-2026-102830
Received Received - Intake

JavaScript Injection in JupyterLab via Plural-Forms Header

Vulnerability report for CVE-2026-102830, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
jupyter jupyterlab From 3.0.0 (inc) to 4.5.11 (inc)
jupyter jupyterlab to 4.6.4 (inc)
jupyter jupyterlite_core to 0.8.4 (exc)
jupyterlab jupyterlab From 3.0.0 (inc) to 4.6.4 (exc)
jupyterlab jupyterlab 4.5.11
jupyterlab jupyterlab 4.6.4
jupyterlite core to 0.8.4 (exc)
jupyterlab notebook From 3.0.0 (inc) to 4.6.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102830 is a code injection vulnerability in JupyterLab caused by improper validation of the Plural-Forms header in third-party language packs. The system converts this header into a JavaScript function using new Function, allowing malicious code appended after a valid plural rule to execute. This happens because the regular expression only checks the start of the header, not the entire string.

Detection Guidance

Detecting this vulnerability requires checking for affected JupyterLab versions and installed language packs. Inspect installed packages with commands like 'pip list | grep jupyterlab' or 'conda list jupyterlab'. Check version numbers against the vulnerable range (3.0.0 to 4.6.3). Review language pack installations with 'jupyter lab list' or checking language settings in the JupyterLab interface.

Impact Analysis

If exploited, this vulnerability allows attackers to execute arbitrary code in the context of an authenticated JupyterLab session. This could lead to unauthorized access to files, running malicious code, starting kernels, or opening terminals. The impact is limited in JupyterLite due to fewer exposed server surfaces. The default English locale is not affected.

Mitigation Strategies

Immediately update JupyterLab to version 4.6.4 or 4.5.11 or later. If updating is not possible, switch to the English locale as a temporary workaround. Remove any non-default language packs until patched versions are installed. Restrict access to Jupyter Server APIs if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102830. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart