Vulnerability Description
JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never execute, so the extension allowlist/blocklist check was not enforced for direct callers of install(). The stock JupyterLab HTTP API and Extension Manager UI are not affected, as they perform a separate, correctly awaited check. The issue affects only deployments where a custom extension or downstream integration imports PyPIExtensionManager and calls install() directly with a package name influenced by untrusted input, an allowlist/blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. Fixed in JupyterLab 4.6.2 and 4.5.10.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-whvh-wf3x-g77j
- https://www.vulncheck.com/advisories/jupyterlab-before-authentication-bypass-via
FAQ
What is CVE-2026-73626?
CVE-2026-73626 is a vulnerability with a CVSS score of 7.5 (HIGH). JupyterLab versions >=4.6.0,<=4.6.1 and <=4.5.9 contain an allowlist/blocklist enforcement gap in PyPIExtensionManager.install(). A missing 'await' caused the is_install_allowed coroutine to never exe...
How severe is CVE-2026-73626?
CVE-2026-73626 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73626?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.