Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
22 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.21% | — | JupyterlabAI | 29/9/2026 | 30/9/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall… | |
| Pendiente de análisis | Alta (8.1) | 0.20% | — | JupyterlabAIJupyter NotebookAIJupyterlite CoreAI | 29/9/2026 | 2/10/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled… | |
| Pendiente de análisis | Media (6.8) | 0.26% | — | JupyterlabAIJupyterlite CoreAI | 29/9/2026 | 29/9/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid… | |
| Pendiente de análisis | Alta (8.6) | 0.75% | — | JupyterlabAI | 13/8/2026 | 18/9/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.10 and 4.6.2, JupyterLab allows notebook settings to be shared and applied through an overrides.json file using the Import button in the Settings Editor. In… | |
| Pendiente de análisis | Media (6.1) | 0.66% | — | JupyterlabAI | 13/8/2026 | 18/9/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.10 and 4.6.2, in jupyterlab/extensions/manager.py and jupyterlab/extensions/pypi.py, JupyterLab's PyPI extension manager enforces blocked_extensions_uris by comparing… | |
| Pendiente de análisis | Alta (7.7) | 0.36% | — | JupyterlabAI | 13/8/2026 | 9/9/2026 | JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab… | |
| Pendiente de análisis | Media (6) | 0.42% | — | JupyterlabAI | 13/8/2026 | 30/9/2026 | JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling… | |
| Pendiente de análisis | Alta (7.5) | 0.74% | — | JupyterlabAI | 12/8/2026 | 9/9/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image and revokes the blob URL too early,… | |
| Pendiente de análisis | Media (5.1) | 0.30% | — | JupyterlabAI | 1/8/2026 | 9/9/2026 | JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when… | |
| Analizada | Alta (7.1) | 0.41% | — | Jupyterlab-git | 8/7/2026 | 15/7/2026 | JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue… | |
| Analizada | Crítica (9.3) | 0.53% | — | Jupyterlab-git | 8/7/2026 | 15/7/2026 | JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History… | |
| Modificada | Alta (8.6) | 0.71% | — | JupyterlabJupyter Notebook | 13/5/2026 | 28/8/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on… | |
| Modificada | Alta (8.8) | 0.85% | — | Jupyterlab | 13/5/2026 | 28/8/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_extensions_uris) is not correctly enforced by JupyterLab. The PyPI Extension… | |
| Pendiente de análisis | Alta (8.4) | 0.66% | — | Jupyter NotebookAIJupyterlabAIJupyter Help-extensionAIJupyterlab Help-extensionAI | 6/5/2026 | 17/6/2026 | In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook… | |
| Analizada | Baja (2.1) | 0.24% | — | Jupyterlab | 26/9/2025 | 17/6/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the noopener attribute. This is deemed… | |
| Aplazada | Alta (7.4) | 0.58% | — | Jupyterlab-gitAI | 3/4/2025 | 17/6/2026 | jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Git repository under a name that includes a shell command substitution string in the syntax $(<command>). These directory names are allowed in macOS and a majority of Linux distributions. If a user… | |
| Analizada | Media (6.1) | 0.40% | — | JupyterlabJupyter Notebook | 28/8/2024 | 17/6/2026 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature. A malicious user can access any data… | |
| Analizada | Crítica (9.8) | 1.1% | — | Jupyterlab | 16/7/2024 | 17/6/2026 | JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest… | |
| Modificada | Media (6.5) | 0.67% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab… | |
| Modificada | Media (6.1) | 0.57% | — | JupyterlabJupyter NotebookFedoraproject Fedora | 19/1/2024 | 17/6/2026 | JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has… | |
| Modificada | Media (5.4) | 0.70% | — | Jupyter NbdimeNbdime-jupyterlab | 3/11/2021 | 17/6/2026 | nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the string it constructs before returning it… | |
| Modificada | Crítica (9.6) | 2.7% | — | Jupyterlab | 9/8/2021 | 17/6/2026 | JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation… |