Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
9 active CVEs reported via OSV.dev
JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
JupyterLab vulnerable to SXSS in Markdown Preview
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Other Developer Tools projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for JupyterLab โ without relying on volunteer maintainers.
Talk to an Expert โ