Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
Published May 6, 2026
8.4
HIGHCVSS 4.0
EPSS 0.66%
Description
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click.
An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.
Affected products
-
- Version >=7.0.0, <= 7.5.5StatusaffectedConstraints-
- Version
-
- Version >=7.0.0,<= 7.5.5StatusaffectedConstraints-
- Version
-
- Version <=4.5.6StatusaffectedConstraints-
- Version
-
- Version <= 4.5.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jupyter | Notebook | n/a |
| ||||||
| Jupyter-Notebook | Help-Extension | n/a |
| ||||||
| Jupyterlab | Help-Extension | n/a |
| ||||||
| Jupyterlab | Jupyterlab | n/a |
|
No data.
No data.
Red Hat Migration Toolkit for Applications 8.2
mta/mta-solution-server-rhel9:1784109883
Fixed · RHSA-2026:43038
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1788315638
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1788185839
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1788185798
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1788185733
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1788185436
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1788185842
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1788185848
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1788186007
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1788185846
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 2.25
rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1788185899
Fixed · RHSA-2026:65126
Red Hat OpenShift AI 3.4
rhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1787074331
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1787073913
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1787074078
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1787073929
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1787073605
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1787073546
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1787073717
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1787073713
Fixed · RHSA-2026:60520
Red Hat OpenShift AI 3.4
rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1787073593
Fixed · RHSA-2026:60520
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Applications 8.2 | mta/mta-solution-server-rhel9:1784109883 | Fixed | RHSA-2026:43038 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1788315638 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1788185839 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1788185798 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1788185733 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1788185436 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:1788185842 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1788185848 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1788186007 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1788185846 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 2.25 | rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1788185899 | Fixed | RHSA-2026:65126 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-th06-cpu-torch210-py312-rhel9:1787076778 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-th06-cuda130-torch210-py312-rhel9:1787077779 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-th06-rocm64-torch291-py312-rhel9:1787076481 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:1787074331 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:1787073913 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:1787074078 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:1787073929 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:1787073605 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:1787073546 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:1787073717 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:1787073713 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI 3.4 | rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:1787073593 | Fixed | RHSA-2026:60520 |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Not affected | n/a |
@jupyter-notebook/help-extension
npm
Introduced 7.0.0 Fixed 7.5.6notebook
PyPI
Introduced 7.0.0 Fixed 7.5.6jupyterlab
PyPI
Introduced 0 Fixed 4.5.7@jupyterlab/help-extension
npm
Introduced 0 Fixed 4.5.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @jupyter-notebook/help-extension | 7.0.0 | 7.5.6 |
| PyPI | notebook | 7.0.0 | 7.5.6 |
| PyPI | jupyterlab | 0 | 4.5.7 |
| npm | @jupyterlab/help-extension | 0 | 4.5.7 |
Remediation
Red Hat statement
This is an Important flaw in Jupyter Notebook and JupyterLab, enabling a stored cross-site scripting (XSS) attack. An attacker can craft a malicious notebook that, with a single user click, can steal authentication tokens and fully compromise the Jupyter session, leading to arbitrary code execution and information disclosure. This impacts Red Hat OpenShift AI and Migration Toolkit for Applications.
Red Hat mitigation
To reduce the risk of exploitation, disable the affected help extensions in Jupyter Notebook and JupyterLab, or set the `allowCommandLinker` option to `false` within the sanitizer configuration. Consult the Jupyter documentation for specific instructions on modifying these settings. Disabling these features may affect the availability of certain help functionalities.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 7, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.66% (0.00663) | 49.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.48% (0.00476) | 37.22th | v5 (v2026.06.15) |
| May 7, 2026 | 0.10% (0.00104) | 27.98th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40171 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467453 Issue Tracking
- https://github.com/advisories/GHSA-rch3-82jr-f9w9 Advisory
- https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9 x_refsource_CONFIRM
- https://jupyterlab.readthedocs.io/en/latest/user/commands.html#commands-in-markdown-output-and-files
- https://nvd.nist.gov/vuln/detail/CVE-2026-40171
- https://www.cve.org/CVERecord?id=CVE-2026-40171
Change history (0)
No recorded changes yet.