CVE-2026-102904
Last modified
CVE-2026-102904 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values.
Description
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, the account can call the extension API, and kernels and terminals are disabled or delegated to remote hosts; otherwise the user can already read files and make outbound requests directly. An authenticated user with extension API access can supply a pip requirements option to make the server read a local file or fetch an internal URL, and reflected parse errors can return the first unparsable line or response content. A pip log option can also create or corrupt a chosen path with pip-generated log text, but the requester cannot select an arbitrary disclosed line or arbitrary file content, and the injection does not add code execution or availability impact beyond ordinary package removal. This issue is fixed in JupyterLab 4.5.11 and 4.6.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| jupyterlab | jupyterlab | >= 4.0.0, < 4.5.11; >= 4.6.0, < 4.6.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-102904?
How severe is CVE-2026-102904?
How do I fix CVE-2026-102904?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-102878mcp-chrome-bridge through 1.0.31 contains an origin validati…8.1
- CVE-2026-102879ClaraVerse through 0.3.1 contains server-side request forger…5
- CVE-2026-10288A vulnerability was identified in code-projects Hotel and To…7.3
- CVE-2026-10289A security flaw has been discovered in code-projects Hotel a…4.3
- CVE-2026-1029IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2…5.4
- CVE-2026-10290A weakness has been identified in code-projects Hotel and To…7.3
- CVE-2026-10291A security vulnerability has been detected in Enderfga claw-…5.3
- CVE-2026-10292A vulnerability was detected in UTT HiPER 1200GW up to 2.5.3…8.8
- CVE-2026-102925virtualenv is a tool for creating isolated virtual python en…7.8
- CVE-2026-10293A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306…8.8
- CVE-2026-102930virtualenv is a tool for creating isolated virtual python en…7.7
- CVE-2026-102937virtualenv is a tool for creating isolated virtual python en…7.3
Are you affected by CVE-2026-102904?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
