Database/AI/ML frameworks & serving
JupyterLab: language-pack Plural-Forms header reaches new Function, executing code in the session origin
Impact
The Plural-Forms header of a selected language pack is validated with a prefix-only regular expression, so JavaScript appended after a valid plural rule passes the check and is then handed to new Function. Loading the catalogue and translating any plural string runs that code in the authenticated JupyterLab origin. Where Jupyter Server exposes kernels, terminals and file APIs - the normal configuration on a GPU node - the injected code can call those authenticated APIs to read or write files and execute code on the accelerator host. Exploitation depends on a user selecting a third-party language pack; the default English locale loads no catalogue and is unaffected, and JupyterLite is much less exposed because it usually has no server APIs behind it.
Who can reach it
Requires a user to install and select a malicious or tampered third-party language pack, so the practical path is a poisoned pack in the environment image or a pip install into the notebook environment. No attacker authentication to the server; the victim's own session provides the credentials.
What to do
Upgrade to JupyterLab 4.5.11 or 4.6.4, or JupyterLite Core 0.8.4, and restart the notebook servers. Until then, keep the default locale and do not install language packs from untrusted sources. Daemon-level change only - no node drain.
References
Related entries
- ONNX: symlink-following external-data write lets a local attacker append to victim-writable filesCVE-2026-49114 · ONNX Python library (save_external_data external-data path handling)Medium
- NVIDIA OpenShell: sandbox exec handler is vulnerable to OS command injection, breaking the sandbox boundaryCVE-2026-65086 · NVIDIA OpenShell for Linux (sandbox exec handler)Medium
- Hugging Face Transformers: checkpoint index shard names traverse out of the model directoryCVE-2026-75104 · Hugging Face Transformers (checkpoint shard index filename handling)Medium
- LangGraph.js MongoDB checkpointer: NoSQL injection in thread ids leaks checkpoints across tenantsCVE-2026-48121 · @langchain/langgraph-checkpoint-mongodb (MongoDBSaver.getTuple checkpoint lookup)Medium
- Ollama: DNS rebinding grants a remote page full API accessCVE-2024-28224 · OllamaMedium
- Dagster (gRPC `get_notebook_data`): Local file inclusion — read arbitrary filesCVE-2025-51481 · Dagster (gRPC `get_notebook_data`)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.