Database/AI/ML frameworks & serving
JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRF
Impact
An authenticated JupyterLab user who can reach the extension API can pass pip options (not just a package name) into python -m pip uninstall, using a requirements option to make the notebook server read a local file or fetch an internal URL, with the first unparsable line or response body reflected back in the parse error. A pip log option can also create or corrupt a chosen path with pip log text. On a GPU fleet this matters mainly for the hardened configuration operators actually use for shared notebooks: kernels and terminals disabled or pushed to remote hosts, where the user is not supposed to have arbitrary local read or egress from the notebook host. There it turns a restricted notebook account into a reader of files the server user can see - service-account tokens, kubeconfigs, cloud metadata reachable from the node. Where kernels and terminals are enabled the user already has those abilities directly, so there is no added exposure. No code execution and no availability impact beyond an ordinary package removal.
Who can reach it
Authenticated JupyterLab user with access to the extension API, in a deployment where the PyPI Extension Manager is enabled. No local access to the node is needed beyond the notebook session.
What to do
Upgrade JupyterLab to 4.5.11 or 4.6.4 and restart the notebook servers; on shared GPU nodes this is a per-server or per-pod restart that kills running kernels, so schedule it with tenants. If an upgrade has to wait, disable the PyPI Extension Manager, or restrict extension-API access to accounts already trusted with local read and outbound network from the notebook host.
References
Related entries
- TorchServe (model/workflow API): Information disclosure of files on the serving hostCVE-2023-48299 · TorchServe (model/workflow API)Medium
- llama.cpp (RPC backend): Arbitrary address read via `rpc_tensor.data`CVE-2024-42478 · llama.cpp (RPC backend)Medium
- HuggingFace transformers: ReDoS in `convert_tf_weight_name_to_pt_weight_name`CVE-2025-5197 · HuggingFace transformersMedium
- BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py): A model repository directory name flows unescapedCVE-2026-15035 · BentoML OpenLLM 0.6.30 (async_run_command in src/openllm/common.py)Medium
- JupyterHub: unauthenticated logins write unbounded usernames to the log, exhausting storageCVE-2026-54338 · JupyterHub form-based login authenticators (failed-login logging)Medium
- vLLM: malformed JSON to the OpenAI-compatible endpoints returns server paths and versionsCVE-2026-73555 · vLLM OpenAI-compatible API server (validation_exception_handler, sanitize_message)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.