CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-42557

Critical · CVSS 9.6

JupyterLab — Stored Cross-Site Scripting (XSS) via HTML cell output leading to arbitrary command execution

CVSS
9.6
nvd
EPSS
0.39%
31th pct
KEV
No
Class
oss containerizable
CWE-79, CWE-79

Description

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.

Search profile — drives PoC discovery

Symbols data-commandlinker-commanddata-commandlinker-argsCommandLinkerdocument.bodyclick eventbuttonHTML sanitizer allowlistnotebook HTML cell output
Keywords CVE-2026-42557JupyterLab CommandLinker XSSJupyterLab arbitrary command executionJupyterLab HTML cell output exploitGHSA-mqcg-5x36-vfcgJupyterLab data-commandlinker-command PoCJupyterLab 4.5.7 vulnerabilityJupyterLab stored XSS notebook
Versions: < 4.5.7

Affected packages

Bitnami jupyter-base-notebook 7.0.0 → 7.5.6
Bitnami jupyter-notebook 7.0.0 → 7.5.6
Bitnami jupyterlab 0 → 4.5.7
PyPI jupyterlab 0 → 4.5.7
PyPI notebook 7.0.0 → 7.5.6

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z