CVE-2026-42557

high
Published 2026-05-13 · Modified 2026-05-14
CVSS v3
CVSS v2
VIR risk
8.0

Description

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-42557

OS impact

OSVersionStatusFixed in
debian debianforkyaffected
debian debiansidaffected
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIjupyterlab<4.5.74.5.7
python PyPInotebook>=7.0.0,<7.5.67.5.6
PIPnotebook>= 7.0.0, <= 7.5.57.5.6
PIPjupyterlab<= 4.5.64.5.7

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.