CVE-2026-73627 PUBLISHED

JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass

Assigner: VulnCheck
Reserved: 13.08.2026 Published: 13.08.2026 Updated: 13.08.2026

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-side enforcement gaps allow an authenticated user to circumvent administrator lock rules by making direct requests to the /lab/api/plugins endpoint, enabling or disabling plugins that were locked — including child plugins of multi-plugin extensions and plugins locked via the 'lock all' mechanism. This can impact data integrity and bypass hardening or restrictions (e.g., download/upload limits) implemented through locked plugins. Fixed in versions 4.6.2 and 4.5.10.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor jupyterlab
Product jupyterlab
Versions Default: affected
  • unaffected from 0 to 4.6.0 (excl.)
Vendor jupyterlab
Product jupyterlab
Versions Default: affected
  • unaffected from 0 to 4.1.0 (excl.)

Credits

  • rexpository reporter
  • MUFFANUJ finder
  • krassowski coordinator

References

Problem Types

  • Client-Side Enforcement of Server-Side Security CWE