[Git][security-tracker-team/security-tracker][master] Add CVE-2026-67338/jupyterlab
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 1 21:17:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5f9bd977 by Salvatore Bonaccorso at 2026-08-01T22:17:20+02:00
Add CVE-2026-67338/jupyterlab
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -25,7 +25,10 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
- guzzle 7.14.2-1
NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
- TODO: check
+ - jupyterlab <unfixed>
+ NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
+ NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
+ NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)
CVE-2026-67337 (better-auth versions before 1.4.9 contain a two-factor authentication ...)
NOT-FOR-US: Better Auth
CVE-2026-67336 (better-auth versions before 1.6.11 contain insecure cryptographic defa ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f9bd9777006029e30dbd58ff0f36d76895b0046
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f9bd9777006029e30dbd58ff0f36d76895b0046
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/3c66d56d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list