Database/AI/ML frameworks & serving
JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated origin
Impact
A notebook cell pasted from the system clipboard is accepted with its attacker-supplied metadata.trusted intact, so crafted HTML output in that cell is treated as trusted, skips output sanitization, and executes JavaScript in the authenticated JupyterLab origin without the user ever running the cell. On a GPU node that means the script inherits the session's Jupyter Server credentials and can drive kernels and file APIs as the notebook user - code execution on the accelerator, not just a browser annoyance. Shared or multi-tenant notebook hosts are the exposure: anyone who can get a researcher to copy a cell from a shared notebook, a chat message, or a pasted snippet reaches the kernel. Requires the non-default combination of useSystemClipboardForCells active and pasteCodeCellsWithoutOutput disabled.
Who can reach it
Remote and unauthenticated on the attacker's side, but needs a logged-in JupyterLab user to paste attacker-supplied cell JSON from the clipboard. No credentials needed by the attacker; the victim supplies the session.
What to do
Upgrade to JupyterLab 4.5.11 or 4.6.4, Notebook 7.6.3, or JupyterLite Core 0.8.4 and restart the notebook servers - each user's server process must be recycled, but no node drain or reboot is involved. As an interim mitigation, re-enable pasteCodeCellsWithoutOutput or turn off useSystemClipboardForCells, which closes the path without a version bump.
References
Related entries
- Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`CVE-2026-11816 · Keras (archive extraction utils)High
- llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`CVE-2026-43629 · llama-server (KV cache state restore)High
- llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsCVE-2026-43632 · llama-server (tokenization endpoints)High
- NVIDIA NemoClaw: installation process executes untrusted codeCVE-2026-65081 · NVIDIA NemoClaw for Linux (installer)High
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyCVE-2026-65084 · NVIDIA NemoClaw for Linux (deployment process, TLS certificate validation)High
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowCVE-2026-65098 · NVIDIA NemoClaw for Linux (remote-access helper workflow)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.