SCA: security update for jupyterlab (GHSA-3325-v43h-43rv)

medium Tenable Self-Hosted Container Security Plugin ID 455123

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter
Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall
request reaches ExtensionHandler.post, which validates extension names for installation but passes
uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-
like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call
the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user
can already read files and make outbound requests directly. An authenticated user with extension API
access can supply a pip requirements option to make the server read a local file or fetch an internal URL,
and reflected parse errors can return the first unparsable line or response content. A pip log option can
also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an
arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or
availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.
(CVE-2026-102904)

Solution

Update the jupyterlab library and its related packages to version 4.5.11 or later.

See Also

https://github.com/advisories/GHSA-3325-v43h-43rv

Plugin Details

Severity: Medium

ID: 455123

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 8.1

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-102904

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/1/2026

Vulnerability Publication Date: 9/29/2026

Reference Information

CVE: CVE-2026-102904