Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 13 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10. | |
| Title | JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager | |
| First Time appeared |
Jupyter
Jupyter jupyterlab |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jupyter
Jupyter jupyterlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T12:57:46.464Z
Reserved: 2026-08-13T11:17:25.160Z
Link: CVE-2026-73626
Updated: 2026-08-13T12:57:41.554Z
Status : Received
Published: 2026-08-13T12:17:27.897
Modified: 2026-08-13T13:19:21.833
Link: CVE-2026-73626
No data.
OpenCVE Enrichment
Updated: 2026-08-13T13:15:04Z
-
CWE-284
Improper Access Control