CVE-2026-42557Jupyter · Jupyterlab
Vulnerability data via NVD (ingested)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlists data-commandlinker-command and data-commandlinker-args on button elements, while CommandLinker listens for all click events on document.body and executes the named command without checking whether the element came from trusted JupyterLab UI. A notebook with a pre-saved HTML cell output containing a deceptive button can trigger arbitrary JupyterLab commands - including arbitrary code execution - on a single user click, without any code being submitted for execution by the user. This vulnerability is fixed in 4.5.7.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-42557product:"Jupyter Jupyterlab"http.html:"Jupyterlab"More intel sources (5)
vuln:CVE-2026-42557vulnerabilities.cve_id: CVE-2026-42557CVE-2026-42557CVE-2026-42557"CVE-2026-42557" exploit -site:nvd.nist.gov