Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungRefreshed repository pull requests page generally available(22.09.2026 um 03:25 Uhr)
Sichere ProgrammierungThe Joy of Learning the Basics Again(22.09.2026 um 03:28 Uhr)
Sichere ProgrammierungZero-Code OpenTelemetry Tracing for Dagster(22.09.2026 um 03:39 Uhr)
Linux Tipps & Hardening`prime-all`(22.09.2026 um 02:28 Uhr)
IT Security Toolsopensoho v0.15.2(22.09.2026 um 03:33 Uhr)
IT Security NachrichtenUS Proposes AI Incident Alert System in Talks With China, Bessent Says(22.09.2026 um 04:01 Uhr)
Sichere ProgrammierungRefreshed repository pull requests page generally available(22.09.2026 um 03:25 Uhr)
Sichere ProgrammierungThe Joy of Learning the Basics Again(22.09.2026 um 03:28 Uhr)
Sichere ProgrammierungZero-Code OpenTelemetry Tracing for Dagster(22.09.2026 um 03:39 Uhr)
Linux Tipps & Hardening`prime-all`(22.09.2026 um 02:28 Uhr)
IT Security Toolsopensoho v0.15.2(22.09.2026 um 03:33 Uhr)
IT Security NachrichtenUS Proposes AI Incident Alert System in Talks With China, Bessent Says(22.09.2026 um 04:01 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer Vulnerability ID: GHSA-GX64-GJ6P-PC4C CVSS Score: 8.2 Published: 2026-07-22 A stored Cross-Site Scripting (XSS) vulnerability exists in JupyterLab's Image…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer




Vulnerability ID: GHSA-GX64-GJ6P-PC4C

CVSS Score: 8.2

Published: 2026-07-22




A stored Cross-Site Scripting (XSS) vulnerability exists in JupyterLab's Image Viewer component when processing Scalable Vector Graphics (SVG) images. Due to the lingering lifecycle of generated object URLs and the inheritance of the application origin by client-side Blobs, an attacker can execute arbitrary JavaScript within the victim's active session. This execution occurs when a user views an SVG file in the JupyterLab image viewer, right-clicks the image, and selects 'Open image in new tab'.






TL;DR



Stored XSS in JupyterLab's image viewer allows arbitrary JavaScript execution and host takeover when a user opens a malicious SVG image in a new browser tab.









⚠️ Exploit Status: POC






Technical Details





  • CWE ID: CWE-79


  • Attack Vector: Network (AV:N)


  • CVSS v3.1: 8.2 (High)


  • Exploit Status: Proof-of-Concept


  • Impact: Stored XSS / Remote Command Execution


  • CISA KEV Status: Not Listed






Affected Systems




  • JupyterLab Server deployments


  • JupyterLab: < 4.5.10 (Fixed in: 4.5.10)


  • JupyterLab: >= 4.6.0, < 4.6.2 (Fixed in: 4.6.2)






Code Analysis






Commit: be9303f



Revoke image object URLs in 4.5.x branch immediately on load/error events to prevent lifetime-based XSS attacks.






Commit: f1beab4



Revoke image object URLs in 4.6.x branch immediately on load/error events to prevent lifetime-based XSS attacks.






Exploit Details





  • GitHub Security Advisory: Proof of concept details detailing how the SVG is embedded with XML JS tags to make calls back to /api/kernels.






Mitigation Strategies




  • Upgrade JupyterLab to version 4.5.10 or 4.6.2

  • Implement a Content Security Policy (CSP) restricting object-src and script-src directives

  • Restrict the uploads of raw SVG files in multi-user shared Jupyter environments

  • Educate developers against using 'Open image in new tab' for untrusted media files



Remediation Steps:




  1. Run 'pip install --upgrade jupyterlab' or 'conda update -c conda-forge jupyterlab' to pull the latest security patch.

  2. Verify the installed version is at least 4.5.10 or 4.6.2.

  3. Restart the JupyterLab server process to ensure the new static assets are served.






References








Read the full report for GHSA-GX64-GJ6P-PC4C on our website for more details including interactive diagrams and full exploit analysis.

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

Thematisch verwandte Begriffe: GHSAGX64GJ6PPC4C, Stored, CrossSite, Scripting · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-49449 | Joplin is an open source note-taking and to-do application that organise…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick