A high-severity flaw in JupyterLab's built-in image viewer lets a specially crafted image file execute cross-site scripting when opened and then re-opened in a new browser tab, and that XSS can be chained into full remote code execution on the JupyterLab server. This matters because JupyterLab underpins notebook-based data science, ML training, and RAG/agent prototyping workflows across roughly 1,876 downstream dependents, and a compromised session typically has access to datasets, model artifacts, and cloud credentials used by the kernel process. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit yet since the advisory published only yesterday (2026-07-22), so treat likelihood as unconfirmed rather than low — the OpenSSF Scorecard of 5.8/10 and 33 prior CVEs in this package suggest a track record worth monitoring. Patch to JupyterLab 4.6.2 or 4.5.10 immediately, or apply the vendor workaround (`jupyter labextension disable @jupyterlab/imageviewer-extension:plugin`) on any server you can't patch today, and verify with `jupyter labextension list`. This is especially urgent for shared JupyterHub/multi-tenant research platforms where users routinely open files from untrusted collaborators or public datasets.
What is the risk?
Rated high severity by the vendor despite the absence of a published CVSS vector, EPSS score, or CISA KEV listing — those gaps reflect the advisory's freshness (published 2026-07-22), not low risk. Exploitation requires user interaction (opening a crafted image, then opening it in a new tab), which lowers the likelihood of mass automated exploitation but does not reduce impact: successful exploitation escalates from client-side XSS to server-side arbitrary code execution. No public exploit or Nuclei template exists yet, but the affected package has a mediocre OpenSSF Scorecard (5.8/10) and a history of 33 other CVEs, indicating JupyterLab is a recurring target. Given the tool's footprint (1,876 dependents) in ML/AI development environments, the realistic risk is concentrated in shared or multi-tenant Jupyter deployments (JupyterHub, hosted notebook services) where untrusted files are routinely opened.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Jupyter | pip | >= 4.6.0, <= 4.6.1 | 4.6.2 |
Do you use Jupyter? You're affected.
How severe is it?
What should I do?
1 step-
Upgrade to JupyterLab 4.6.2 or 4.5.10, which contain the patch. If immediate patching isn't possible, disable the vulnerable extension with
jupyter labextension disable @jupyterlab/imageviewer-extension:pluginand confirm withjupyter labextension list. Audit shared/multi-tenant JupyterHub deployments for any custom image-preview or file-sharing workflows that could deliver a crafted image to end users. For detection, review browser/network logs for anomalous JupyterLab kernel-execution API calls immediately following an image-viewer 'open in new tab' action, and treat any unexpected kernel command execution as a potential indicator of compromise.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is GHSA-gx64-gj6p-pc4c?
A high-severity flaw in JupyterLab's built-in image viewer lets a specially crafted image file execute cross-site scripting when opened and then re-opened in a new browser tab, and that XSS can be chained into full remote code execution on the JupyterLab server. This matters because JupyterLab underpins notebook-based data science, ML training, and RAG/agent prototyping workflows across roughly 1,876 downstream dependents, and a compromised session typically has access to datasets, model artifacts, and cloud credentials used by the kernel process. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit yet since the advisory published only yesterday (2026-07-22), so treat likelihood as unconfirmed rather than low — the OpenSSF Scorecard of 5.8/10 and 33 prior CVEs in this package suggest a track record worth monitoring. Patch to JupyterLab 4.6.2 or 4.5.10 immediately, or apply the vendor workaround (`jupyter labextension disable @jupyterlab/imageviewer-extension:plugin`) on any server you can't patch today, and verify with `jupyter labextension list`. This is especially urgent for shared JupyterHub/multi-tenant research platforms where users routinely open files from untrusted collaborators or public datasets.
Is GHSA-gx64-gj6p-pc4c actively exploited?
No confirmed active exploitation of GHSA-gx64-gj6p-pc4c has been reported, but organizations should still patch proactively.
How to fix GHSA-gx64-gj6p-pc4c?
Upgrade to JupyterLab 4.6.2 or 4.5.10, which contain the patch. If immediate patching isn't possible, disable the vulnerable extension with `jupyter labextension disable @jupyterlab/imageviewer-extension:plugin` and confirm with `jupyter labextension list`. Audit shared/multi-tenant JupyterHub deployments for any custom image-preview or file-sharing workflows that could deliver a crafted image to end users. For detection, review browser/network logs for anomalous JupyterLab kernel-execution API calls immediately following an image-viewer 'open in new tab' action, and treat any unexpected kernel command execution as a potential indicator of compromise.
What systems are affected by GHSA-gx64-gj6p-pc4c?
This vulnerability affects the following AI/ML architecture patterns: notebook-based ML development environments, training pipelines, shared multi-tenant research platforms (JupyterHub), MLOps developer tooling.
What is the CVSS score for GHSA-gx64-gj6p-pc4c?
No CVSS score has been assigned yet.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0010.001 AI Software AML.T0011 User Execution AML.T0050 Command and Scripting Interpreter Compliance Controls Affected
What are the technical details?
Original Advisory
JupyterLab's image viewer allows for cross-site scripting (XSS) when a specially-crafted image file is opened through the image viewer and then opened in a new tab. This XSS issue can be used to cause remote code execution (RCE) on the JupyterLab server. ### Impact This vulnerability allows for arbitrary code execution. ### Patches JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch. ### Workarounds Disable the image viewer plugin: ``` jupyter labextension disable @jupyterlab/imageviewer-extension:plugin ``` Confirm with: ``` jupyter labextension list ```
Exploitation Scenario
An attacker uploads or shares a crafted image file — for example, embedded in a public dataset, a shared research repository, or a malicious notebook attachment — targeting a data scientist or ML engineer using JupyterLab. The victim opens the image in JupyterLab's built-in image viewer and then opens it in a new browser tab, triggering the embedded XSS payload in the browser's authenticated JupyterLab session context. The script leverages the victim's session token to call the Jupyter kernel/REST API and submit arbitrary code for execution on the underlying kernel process, achieving remote code execution on the JupyterLab server. From there, the attacker can exfiltrate training data, model weights, or cloud/API credentials accessible to that notebook environment, or pivot further into the organization's ML infrastructure.
Weaknesses (CWE)
CWE-79 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'): The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
- [Architecture and Design] Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Examples of libraries and frameworks that make it easier to generate properly encoded output include Microsoft's Anti-XSS library, the OWASP ESAPI Encoding module, and Apache Wicket.
- [Implementation, Architecture and Design] Understand the context in which your data will be used and the encoding that will be expected. This is especially important when transmitting data between different components, or when generating outputs that can contain multiple encodings at the same time, such as web pages or multi-part mail messages. Study all expected communication protocols and data representations to determine the required encoding strategies. For any data that will be output to another web page, especially any data that was received from external inputs, use the appropriate encoding on all non-alphanumeric characters. Parts of the same output document may require different encodings, which will vary depending on whether the output is in the: etc. Note that HTML Entity Encoding is only appropriate for the HTML body. Consult the XSS Prevention Cheat Sheet [REF-724] for more details on the types of encoding and escaping that are needed. HTML body Element attributes (such as src="XYZ") URIs JavaScript sections Casca
Source: MITRE CWE corpus.
References
- github.com/advisories/GHSA-gx64-gj6p-pc4c
- github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
- github.com/jupyterlab/jupyterlab/commit/f1beab4a2027af4719d6edc07d52d6cf5a39a432
- github.com/jupyterlab/jupyterlab/pull/19184
- github.com/jupyterlab/jupyterlab/pull/19185
- github.com/jupyterlab/jupyterlab/pull/19186
- github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
Timeline
Related Vulnerabilities
CVE-2023-25574 10.0 JupyterHub LTI13: JWT forgery enables full auth bypass
Same package: jupyter CVE-2026-44180 9.8 Jupyter Enterprise Gateway: root privilege bypass in Kubernetes
Same package: jupyter CVE-2026-23537 9.1 Feast: unauth file write to RCE via /save-document
Same package: jupyter CVE-2026-54527 9.0 jupyterlab-git: stored XSS escalates to full RCE
Same package: jupyter CVE-2026-44727 9.0 jupyter-server: stored XSS yields kernel RCE
Same package: jupyter