Vulnerability library
Security checkMay 08, 2026

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).

Recommendation

Update the @jupyterlab/help-extension package to the latest compatible version. Followings are version details:

  • Affected version(s): <= 4.5.6
  • Patched version(s): 4.5.7

References

Could your website be exposed too?

SmartScanner can check your website for Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 08, 2026