Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
- Severity:
- High
Description
A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).
Recommendation
Update the @jupyterlab/help-extension package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.5.6
- Patched version(s): 4.5.7
References
- GHSA-rch3-82jr-f9w9
- jupyterlab.readthedocs.io
- CVE-2026-40171
- CWE-601
- CWE-79
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State - CVE-2026-42573
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag - CVE-2026-30830
You might also like:
- Tags:
- npm
- @jupyterlab/help-extension
Anything's wrong? Let us know Last updated on May 08, 2026


