PULSE
FEED
ransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technologyransomulose reclama a www.newyjh.com · KR · Not Foundransomstorm reclama a West County Health Centers · US · Healthcareransomstorm reclama a Gardeners' Guild · US · Agriculture and Food Productionransomthegentlemen reclama a LegalWise · ZA · Professional Servicesransomthegentlemen reclama a Samwumed · KR · Healthcareransomthegentlemen reclama a Edcon · ZA · Manufacturingransomthegentlemen reclama a Defencebit · GB · Government & Defenseransomthegentlemen reclama a Datacomm Services · US · Technologyransomthegentlemen reclama a Webb Electric Company of Florida · US · Energy & Utilitiesransomthegentlemen reclama a Solaria · ID · Energy & Utilitiesransomthegentlemen reclama a Auren · ES · Professional Servicesransomthegentlemen reclama a QUALITY SPORT Topsport Italia · IT · Retail & E-Commerceransomthegentlemen reclama a Europrim · FR · Healthcareransomthegentlemen reclama a Telrad Networks · IL · Technology
← All CVEs
CVE WatchSep 29, 2026

CVE-2026-102830

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From Jupyter

CVSS

6.8

Medium

EPSS

—

KEV

—

Exploit Today

0

0-100

Published: Sep 29, 2026 · Last modified: Sep 29, 2026 · CWE-79 · CWE-94

EPSS · 30d

Not enough EPSS history yet.

Technical description

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new Function, so loading the catalogue and translating a plural string executes the appended code in the authenticated JupyterLab origin. Where Jupyter Server kernels, terminals, and APIs are exposed, the code can use authenticated server APIs to read or modify files and run code. Impact is much more limited in JupyterLite because it typically lacks most exposed Jupyter Server surfaces. The default English locale is unaffected because it does not load a translation catalogue. This issue is fixed in JupyterLab 4.5.11 and 4.6.4 and JupyterLite Core 0.8.4.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-973016.5 MED
—
———Contributor Cross Site Scripting (XSS) in Cool Formkit Lite <= 2.7.8 versions.34m
CVE-2026-972986.5 MED
—
———Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.86 versions.34m
CVE-2026-972926.5 MED
—
———Author Cross Site Scripting (XSS) in YITH WooCommerce Tab Manager <= 2.15.0 versions.34m
CVE-2026-972897.1 HIG
—
———Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.34m
CVE-2026-972886.5 MED
—
———Contributor Cross Site Scripting (XSS) in OAuth Server <= 4.5.1 versions.34m
CVE-2026-972866.5 MED
—
———Contributor Cross Site Scripting (XSS) in Strong Testimonials <= 3.3.11 versions.34m