GPU VulnDB

Database/AI/ML frameworks & serving

JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated origin

CVSS 8.1CVE-2026-102831AI/ML frameworks & servingcurated

Impact

A notebook cell pasted from the system clipboard is accepted with its attacker-supplied metadata.trusted intact, so crafted HTML output in that cell is treated as trusted, skips output sanitization, and executes JavaScript in the authenticated JupyterLab origin without the user ever running the cell. On a GPU node that means the script inherits the session's Jupyter Server credentials and can drive kernels and file APIs as the notebook user - code execution on the accelerator, not just a browser annoyance. Shared or multi-tenant notebook hosts are the exposure: anyone who can get a researcher to copy a cell from a shared notebook, a chat message, or a pasted snippet reaches the kernel. Requires the non-default combination of useSystemClipboardForCells active and pasteCodeCellsWithoutOutput disabled.

Who can reach it

Remote and unauthenticated on the attacker's side, but needs a logged-in JupyterLab user to paste attacker-supplied cell JSON from the clipboard. No credentials needed by the attacker; the victim supplies the session.

What to do

Upgrade to JupyterLab 4.5.11 or 4.6.4, Notebook 7.6.3, or JupyterLite Core 0.8.4 and restart the notebook servers - each user's server process must be recycled, but no node drain or reboot is involved. As an interim mitigation, re-enable pasteCodeCellsWithoutOutput or turn off useSystemClipboardForCells, which closes the path without a version bump.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.