云虫漏洞库

CVE-2026-42266 - JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7. - 漏洞详情

漏洞编号:CVE-2026-42266

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-42266

CNNVD 编号:-

厂商/产品:jupyter / jupyterlab

影响范围:cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*

CWE:CWE-88

发布/更新时间:2026-05-13 / 2026-08-28

漏洞描述

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension Manager was not contained to packages listed on the default PyPI index. This vulnerability is fixed in 4.5.7.

相关链接

相关漏洞

« 返回首页