Security releases: JupyterLab v4.6.2 and v4.5.10

JupyterLab v4.6.2 and v4.5.10 carry a set of security patches.

High severity:

  • GHSA-gx64-gj6p-pc4c - Image viewer in JupyterLab allows XSS when opening malicious image in new browser tab
  • GHSA-pppj-hq3g-57pj - Cross-site scripting (XSS) in JupyterLab via crafted settings file (`overrides.json`)

Moderate severity:

Low severity:

  • GHSA-whvh-wf3x-g77j - low - Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
1 Like