highVulnerability

GHSA-gx64-gj6p-pc4c

JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ### Impact This vulnerability allows for arbitrary code execution. ### Patches JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch. ### Workarounds Disable the image viewer plugin: ``` jupyter labextension disable @jupyterlab/imageviewer-extension:plugin ``` Confirm with: ``` jupyter labextension list ```

Properties

ghsa_id
GHSA-gx64-gj6p-pc4c
severity
high
summary
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
cve_id
GHSA-gx64-gj6p-pc4c
is_ghsa_only
true
ghsa_published
2026-07-22T23:14:44Z
source_url
https://github.com/advisories/GHSA-gx64-gj6p-pc4c
ghsa_updated
2026-07-22T23:14:46Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/jupyterlab

AFFECTS (1)

[Software]pip/jupyterlab

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-gx64-gj6p-pc4c — Ninja Signal Threat Intelligence | Ninja Signal