OSS Support Hub / Developer Tools

Python Developer Tools BSD-3-Clause Latest: v4.6.3

JupyterLab

Web-based interactive development environment for Jupyter notebooks, code, and data

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

15.3K+28
GitHub Stars
📦
v4.6.3
Latest Release · 14 days ago
🔄
7d
Avg. Release Cadence
🐛
2.6K
Open Issues
📅
5 days ago
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-08-24

Known Vulnerabilities

10 active CVEs reported via OSV.dev

JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request

Published: 2026-05-05 Fixed in: 4.5.7

JupyterLab vulnerable to potential authentication and CSRF tokens leak

Published: 2024-01-19 Fixed in: 4.0.11

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

Published: 2021-08-23 Fixed in: 1.2.21

JupyterLab vulnerable to SXSS in Markdown Preview

Published: 2024-01-19 Fixed in: 4.0.11

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

Published: 2026-07-22 Fixed in: 4.6.2

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

Published: 2024-08-29 Fixed in: 3.6.8

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

Published: 2026-07-22 Fixed in: 4.6.2

JupyterLab PluginManager lock-rule enforcement bypass

Published: 2026-07-22 Fixed in: 4.6.2

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

Published: 2026-05-06 Fixed in: 4.5.7

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

Published: 2026-07-22 Fixed in: 4.6.2

Alternatives to JupyterLab

Other Developer Tools projects in the Python ecosystem worth evaluating.

Support Options for JupyterLab

Commercial Support from DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for JupyterLab — without relying on volunteer maintainers.