jupyterlab
1 advisory in the AI Sec Watch database names jupyterlab. No LLM component dependency is recorded for jupyterlab (PyPI). The most recent advisory that names jupyterlab and states a fix gives 4.5.7.
JupyterLab computational environment
Advisories
Advisories that name jupyterlab as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-40171GHSA-rch3-82jr-f9w9: Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS | High | <= 4.5.6 | 4.5.7 | 2026-04-30 |
Dependencies of the latest release
As declared in PyPI metadata for version 4.6.4. Optional extras are listed with their extra name.
- altair[docs-screenshots]
- async-lru
- build[dev]
- bump2version[dev]
- copier[upgrade-extension]
- coverage[dev]
- hatch[dev]
- httpx
- ipykernel
- ipython[docs-screenshots]
- ipywidgets[docs-screenshots]
- jinja2
- jinja2-time[upgrade-extension]
- jupyter-builder
- jupyter-core
- jupyterlab-geojson[docs-screenshots]
- jupyterlab-language-pack-zh-cn[docs-screenshots]
- jupyterlab-server
- jupyter-lsp
- jupyter-server
- matplotlib[docs-screenshots]
- nbconvert[docs-screenshots]
- notebook-shim
- packaging
- pandas[docs-screenshots]
- pre-commit[dev]
- pydantic[upgrade-extension]
- pytest[test]
- pytest-check-links[test]
- pytest-console-scripts[test]
- pytest-cov[dev]
- pytest-jupyter[test]
- pytest-timeout[test]
- pytest-tornasync[test]
- pytest-xdist[test]
- pyyaml-include[upgrade-extension]
- requests[test]
- requests-cache[test]
- ruff[dev]
- scipy[docs-screenshots]
- shellcheck-py[dev]
- tomli
- tomli-w[upgrade-extension]
- tornado
- traitlets
- typing-extensions
- virtualenv[test]
Tracked packages that depend on it
Among the packages in the registry; not every dependent on PyPI.