Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) Moderate
CVE-2026-102830 was published for jupyterlab (pip) Oct 1, 2026
mingijunggrape Credited to mingijunggrape, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab: PyPI extension blocklist package-name canonicalization bypass Moderate
CVE-2026-73416 was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol Moderate
GHSA-vmhf-c436-hxj4 was published for jupyterlab (pip) Jun 19, 2026
krassowski Credited to krassowski and Yann-P Yann-P Yann-P
jupyter-scheduler's endpoint is missing authentication Moderate
CVE-2024-28188 was published for jupyter-scheduler (pip) May 23, 2024
krassowski Credited to krassowski, Carreau, andrii-i, dlqqq, and yuvipanda Carreau Carreau
andrii-i andrii-i dlqqq dlqqq yuvipanda yuvipanda
ProTip! Advisories are also available from the GraphQL API