Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
JupyterLab vulnerable to SXSS in Markdown Preview
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab PluginManager lock-rule enforcement bypass
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
Other Developer Tools projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for JupyterLab — without relying on volunteer maintainers.