JupyterLab is affected by high-severity vulnerabilities that can lead to arbitrary code execution, security restriction bypass, and information disclosure, prompting an alert from Italy's national cybersecurity agency. The most detailed issue disclosed is CVE-2026-73417, a cross-site scripting flaw caused by improper validation of notebook margin override settings before they are inserted into style content.
An attacker can exploit CVE-2026-73417 by persuading a user to import a malicious overrides.json settings file or by placing that file in a shared settings location so it is applied automatically. Successful exploitation allows code to run with the victim's privileges, enabling reading or modifying notebooks and files and executing code through the notebook server, including on a connected kernel. The flaw affects JupyterLab versions 3.3.0 through 4.5.9 and 4.6.0 through 4.6.1; fixes are available in 4.5.10 and 4.6.2, and organizations are advised to update vulnerable installations in line with vendor guidance.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On August 13, 2026, the CVE record for CVE-2026-73417 was published, describing a high-severity JupyterLab XSS vulnerability affecting versions from 3.3.0 to before 4.5.10 and 4.6.0 to before 4.6.2. The record links the flaw to GitHub advisory GHSA-pppj-hq3g-57pj and recommends updating to fixed versions.
CSIRT Italia reported two high-severity vulnerabilities in JupyterLab that could enable arbitrary code execution, bypass security restrictions, and disclose information. The notice said affected versions include 4.5.9 and earlier and 4.6.0 through 4.6.1, and advised users to apply vendor updates.
JupyterLab addressed a high-severity cross-site scripting flaw, CVE-2026-73417, in releases 4.5.10 and 4.6.2. The issue could allow crafted settings in overrides.json to execute code with the victim user's privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.