GPU VulnDB

Database/AI/ML frameworks & serving

JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRF

CVSS 5.4CVE-2026-102904AI/ML frameworks & servingcurated

Impact

An authenticated JupyterLab user who can reach the extension API can pass pip options (not just a package name) into python -m pip uninstall, using a requirements option to make the notebook server read a local file or fetch an internal URL, with the first unparsable line or response body reflected back in the parse error. A pip log option can also create or corrupt a chosen path with pip log text. On a GPU fleet this matters mainly for the hardened configuration operators actually use for shared notebooks: kernels and terminals disabled or pushed to remote hosts, where the user is not supposed to have arbitrary local read or egress from the notebook host. There it turns a restricted notebook account into a reader of files the server user can see - service-account tokens, kubeconfigs, cloud metadata reachable from the node. Where kernels and terminals are enabled the user already has those abilities directly, so there is no added exposure. No code execution and no availability impact beyond an ordinary package removal.

Who can reach it

Authenticated JupyterLab user with access to the extension API, in a deployment where the PyPI Extension Manager is enabled. No local access to the node is needed beyond the notebook session.

What to do

Upgrade JupyterLab to 4.5.11 or 4.6.4 and restart the notebook servers; on shared GPU nodes this is a per-server or per-pod restart that kills running kernels, so schedule it with tenants. If an upgrade has to wait, disable the PyPI Extension Manager, or restrict extension-API access to accounts already trusted with local read and outbound network from the notebook host.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.