Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-3jqq-pw4j-pqcj

MediumCVSS 6.8 / 10
Published Oct 1, 2026·Last modified Oct 1, 2026
Affected Components(3)
PyPI logojupyterlite-core
< 0.8.4
PyPI logojupyterlab
4.6.0 – 4.6.4
PyPI logojupyterlab
3.0.0 – 4.5.11
Description

Description

A language pack ships a Plural-Forms header saying how the language counts, for example nplurals=2; plural=(n != 1);. JupyterLab turns that string into a function with new Function, so the header gets executed. The check that meant to keep it safe was a regular expression. The regex was anchored at the start but not at the end, so it accepted any string that began with a valid plural rule and ignored everything after it.

A header such as the following passed the check, and the part after the plural rule ran in the JupyterLab page as soon as the first plural string was translated:

nplurals=2; plural=(n > 1); <anything here ran as JavaScript>

Users are affected if all of the following are true:

  • they run JupyterLab 3.0.0 through 4.6.3, or an application that bundles it such as Notebook 7;
  • a language pack they did not write is installed in the environment; and
  • that language is selected, so its catalogue is loaded

An installation using the default English locale loads no catalogue and is not affected.

CVE assignment pending, GitHub CNA is experiencing severe backlog

Impact

The code in the header ran in the JupyterLab page, in the same origin and session as the authenticated user. It could call the Jupyter Server REST API as that user: read and write any file under the server root, start a kernel and run code in it, and open a terminal where terminals are enabled. Nothing had to be clicked; translating one plural string was enough, and that happens during normal use of the interface.

What this changes is who has to be trusted. A language pack is a Python package, and installing one is already a privileged act, so an attacker who can get any package installed has server-side code execution regardless of this issue. The header is different because it is catalogue metadata: it travels with translation content, through the translation pipeline that carries strings from Crowdin into the language packs, and it is reviewed as text rather than as code. Anyone able to change a catalogue, or to publish a pack under a name someone installs, got JavaScript execution in every browser that selected that language.

Note: the impact is much more limited on JupyterLite which typically does not have access to most of the surfaces that this flaw exposes.

Patches

JupyterLab v4.6.4 and v4.5.11 contain the patch. The check now has to match the whole header, so a plural rule followed by anything else is rejected and no function is built from it.

JupyterLab 3.x reached end of life and receives no patch. Its users should move to a supported 4.x release.

Users of applications that depend on JupyterLab, such as Notebook v7+, should update jupyterlab package too.

Workarounds

Use the English locale, which loads no catalogue:

jupyter lab --LabApp.default_locale=en

or the following traitlet:

c.LabApp.default_locale = 'en'

Everyone then sees the interface in English, whatever language they had selected.

To check what is installed instead of switching, report any pack whose header carries more than a plural rule:

python -c "
import re
from jupyterlab_server.translation_utils import get_language_packs, get_language_pack
ok = re.compile(r'\s*nplurals\s*=\s*\d+\s*;\s*plural\s*=[\s\-?|&=!<>+*/%:;n0-9_()]+')
packs, _ = get_language_packs()
for locale in packs:
    data, _ = get_language_pack(locale)
    for domain, catalog in (data or {}).items():
        header = catalog.get('', {}).get('plural_forms')
        if header and not ok.fullmatch(header):
            print('SUSPECT', locale, domain, repr(header))
"

The command prints nothing when every catalogue is sound. A line of output names the pack to remove.

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
6.8

The vulnerability can be exploited over the network without needing physical access. It is difficult for an attacker to exploit this vulnerability and may require special conditions. An attacker does not need any special privileges or access rights. The attacker needs the user to perform some action, like clicking a link. The impact is confined to the system where the vulnerability exists. There is a high impact on the confidentiality of the information. There is a high impact on the integrity of the data.

Threat Intelligence
6.2

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.26%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard