Description
A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).
Recommendation
Update the @jupyterlab/help-extension package to the latest compatible version. Followings are version details:
- Affected version(s): <= 4.5.6
- Patched version(s): 4.5.7
References
Could your website be exposed too?
SmartScanner can check your website for Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS and gives you actionable findings to investigate.
Start a free scanRelated Issues
- HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft - CVE-2026-46496
- Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State - CVE-2026-42573
- CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage - CVE-2026-26862
- defuddle vulnerable to XSS via unescaped string interpolation in _findContentBySchemaText image tag - CVE-2026-30830


