CVE-2026-73415EPSS p44.5%
CVE-2026-73415CVE-2026-73415
Description
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early, allowing the image to retain an executable same-origin context when it is opened through the image viewer and then opened in a new browser tab. The resulting cross-site scripting can be used to execute arbitrary code on the JupyterLab server. This issue is fixed in versions 4.5.10 and 4.6.2.
Scoring
| EPSS | 0.57% probability of exploitation · percentile 44.5% · 2026-08-13T12:03:51Z |
| Last modified | 2026-08-12 |