CVE-2026-102904 | JupyterLab up to 4.5.10/4.6.3 PyPI Extension Manager ExtensionHandler.post injection

SecurityVulns

A vulnerability was found in JupyterLab up to 4.5.10/4.6.3. It has been classified as critical. This affects the function ExtensionHandler.post of the component PyPI Extension Manager. This manipulation causes injection.

This vulnerability is tracked as CVE-2026-102904. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More