CVE-2026-102904
Awaiting Analysis Awaiting Analysis - Queue

JupyterLab PyPI Extension Manager Path Traversal

Vulnerability report for CVE-2026-102904, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
jupyter jupyterlab From 4.0.0 (inc) to 4.5.11 (inc)
jupyter jupyterlab 4.5.11
jupyter jupyterlab 4.6.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JupyterLab versions 4.0.0 to 4.5.11 and 4.6.4 have a flaw in the PyPI Extension Manager. When uninstalling extensions, the system fails to properly validate uninstall names, allowing users to pass pip options. This can lead to reading local files, fetching internal URLs, or creating/corrupting files via pip logs.

Detection Guidance

To detect this vulnerability, check the installed version of JupyterLab. If it is between 4.0.0 and 4.5.11 or 4.6.0 and 4.6.3, it is vulnerable. Run: pip show jupyterlab or jupyter lab --version to check the version.

Impact Analysis

An authenticated user with extension API access could exploit this to read sensitive files, access internal resources, or modify files on the server. However, the impact is limited unless kernels/terminals are disabled or remote, as users could otherwise perform these actions directly.

Mitigation Strategies

Upgrade JupyterLab to version 4.5.11, 4.6.4, or later immediately. Use: pip install --upgrade jupyterlab. Disable the PyPI Extension Manager if not needed to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102904. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart