After a two-year long hiatus, JupyterLab Desktop 4.6.2-1 is out with patches for two critical and two moderate severity vulnerabilities:
- GHSA-vrj4-r4fw-9rfh - pasting a malicious server URL into the connect dialog could lead to remote code execution (XSS)
- GHSA-2mr8-962v-wc67 - one-click server token leak in untrusted notebook leading to remote code execution
- GHSA-8cvf-4977-r95v CVE-2025-54991 - local attacker could inject code into app process to bypass macOS privacy controls (TCC)
- GHSA-5c3f-5gj7-p9xh CVE-2025-55002 - local attacker could run arbitrary code in app context to bypass macOS privacy controls (TCC)
plus all patches inherited from JupyterLab 4.6.2 Security releases: JupyterLab v4.6.2 and v4.5.10