GPU VulnDB

Database/AI/ML frameworks & serving

JupyterLab: language-pack Plural-Forms header reaches new Function, executing code in the session origin

CVSS 6.8CVE-2026-102830AI/ML frameworks & servingcurated

Impact

The Plural-Forms header of a selected language pack is validated with a prefix-only regular expression, so JavaScript appended after a valid plural rule passes the check and is then handed to new Function. Loading the catalogue and translating any plural string runs that code in the authenticated JupyterLab origin. Where Jupyter Server exposes kernels, terminals and file APIs - the normal configuration on a GPU node - the injected code can call those authenticated APIs to read or write files and execute code on the accelerator host. Exploitation depends on a user selecting a third-party language pack; the default English locale loads no catalogue and is unaffected, and JupyterLite is much less exposed because it usually has no server APIs behind it.

Who can reach it

Requires a user to install and select a malicious or tampered third-party language pack, so the practical path is a poisoned pack in the environment image or a pip install into the notebook environment. No attacker authentication to the server; the victim's own session provides the credentials.

What to do

Upgrade to JupyterLab 4.5.11 or 4.6.4, or JupyterLite Core 0.8.4, and restart the notebook servers. Until then, keep the default locale and do not install language packs from untrusted sources. Daemon-level change only - no node drain.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.