Description
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.
Published: 2026-08-13
Score: 0 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in JupyterLab’s PyPIExtensionManager.install() method allows the configured allowlist and blocklist to be bypassed because a missing await statement prevents the is_install_allowed coroutine from executing for callers that invoke install() directly. This gap means that, if an untrusted input is supplied as a package name, the extension can be installed without any of the normal authorization checks, giving the installer privileged access to the JupyterLab environment.

Affected Systems

The vulnerability affects JupyterLab versions 4.5.9 and 4.6.0 through 4.6.1 when the PyPIExtensionManager is used directly. Deployment must have a custom extension or downstream integration that imports PyPIExtensionManager and calls install() with a package name derived from untrusted input, the allowlist/blocklist configuration must be present, the PyPI Extension Manager feature must be enabled, and kernels and terminals must be disabled or delegated to remote hosts to fully expose the flaw.

Risk and Exploitability

EPSS information is not provided and the issue is not listed in the CISA KEV catalog; however, once the preconditions are met the flaw can allow an attacker to install arbitrary extensions that run with the full privileges of the JupyterLab process. The risk is therefore high in environments that meet these specific conditions, while systems that do not expose install() directly or lack an active allowlist/blocklist have a lower probability of exploitation.

Generated by OpenCVE AI on August 13, 2026 at 13:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to JupyterLab version 4.6.2 or 4.5.10 to apply the official fix.
  • If an upgrade is not feasible, patch the PyPIExtensionManager.install() code to include the missing await so that is_install_allowed runs before the installation proceeds.
  • Restrict direct calls to PyPIExtensionManager.install by disabling or sandboxing custom extensions or downstream integrations that could supply untrusted input, and verify that the allowlist/blocklist is active and that kernels and terminals remain disabled or are efficiently delegated to remote hosts.

Generated by OpenCVE AI on August 13, 2026 at 13:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.
Title JupyterLab before 4.6.2 Authentication Bypass via PyPIExtensionManager
First Time appeared Jupyter
Jupyter jupyterlab
Weaknesses CWE-284
CPEs cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*
Vendors & Products Jupyter
Jupyter jupyterlab
References
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N'}

cvssV4_0

{'score': 0, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Jupyter Jupyterlab
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T12:57:46.464Z

Reserved: 2026-08-13T11:17:25.160Z

Link: CVE-2026-73626

cve-icon Vulnrichment

Updated: 2026-08-13T12:57:41.554Z

cve-icon NVD

Status : Received

Published: 2026-08-13T12:17:27.897

Modified: 2026-08-13T13:19:21.833

Link: CVE-2026-73626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T13:15:04Z

Weaknesses