JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content (CVE-2026-42557)
Description
JupyterLab versions prior to 4.5.7 and 4.6.3 contain a vulnerability where HTML sanitizer allowlists certain attributes on button elements, enabling one-click execution of arbitrary JupyterLab commands from untrusted HTML content. This can lead to arbitrary code execution, file deletion, and denial of service by exhausting server resources. The vulnerability is exploitable by convincing a user to click a deceptive button embedded in notebook outputs or Markdown files. Multi-click attacks on Chromium-based browsers can escalate to terminal command execution. No workarounds exist for end-users, but patched versions and configuration options to disable the command linker are available.
CVSS v3.1
Score 9.6critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
JupyterLab's HTML sanitizer allowlists `data-commandlinker-command` and `data-commandlinker-args` attributes on button elements, and the CommandLinker listens for clicks on the document body to execute commands without verifying the source element's trustworthiness. This allows an attacker to embed malicious buttons in notebook outputs or Markdown files that, when clicked by a user, execute arbitrary commands including code execution, file deletion, and resource exhaustion. Multi-click attacks combined with clipboard or keyboard access on Chromium browsers can lead to terminal command execution with potentially broader access. The vulnerability affects JupyterLab versions before 4.5.7 and 4.6.3. The issue is mitigated by updating to patched versions and optionally disabling the CommandLinker functionality via configuration.
Potential Impact
An attacker can execute arbitrary code in JupyterLab kernels, delete files causing potential data loss, and launch multiple kernels or terminals to degrade server availability. The attack requires user interaction (click) but no kernel startup is needed to trigger commands. Multi-click attacks on Chromium browsers can escalate to terminal command execution if clipboard or keyboard access is granted. The impact extends with third-party frontend extensions that add commands, increasing the attack surface. The arbitrary code execution is visible to users and can be stopped, but file deletion may go unnoticed. Denial of service can affect standalone multi-tenant deployments more severely than JupyterHub.
Mitigation Recommendations
A patch is available in JupyterLab version 4.5.7 and later. Users should upgrade to these versions to remediate the vulnerability. No workarounds are available for end-users. Downstream applications can disable the CommandLinker by initializing it with an empty CommandRegistry. Additionally, the patched versions provide a configuration toggle to disable the CommandLinker functionality entirely via the `overrides.json` file by setting `allowCommandLinker` to false. Users should apply these mitigations as appropriate.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BIT-jupyterlab-2026-42557
- Osv Schema Version
- 1.6.2
- Aliases
- ["CVE-2026-42557"]
- Ecosystems
- ["Bitnami"]
- Database Specific Severity
- High
Threat ID: 6a4c347627e9c79719603fe0
Added to database: 07/06/2026, 23:04:22 UTC
Last enriched: 10/03/2026, 18:19:29 UTC
Last updated: 10/04/2026, 18:53:16 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.