[Git][security-tracker-team/security-tracker][master] Add CVE-2026-67338/jupyterlab

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 1 21:17:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f9bd977 by Salvatore Bonaccorso at 2026-08-01T22:17:20+02:00
Add CVE-2026-67338/jupyterlab

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -25,7 +25,10 @@ CVE-2026-67339 (guzzlehttp/guzzle versions before 7.14.2 fail to properly isolat
 	- guzzle 7.14.2-1
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-94pj-82f3-465w
 CVE-2026-67338 (JupyterLab before 4.5.9 contains a stored cross-site scripting vulnera ...)
-	TODO: check
+	- jupyterlab <unfixed>
+	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-vmhf-c436-hxj4
+	NOTE: https://github.com/jupyterlab/jupyterlab/commit/4e61e07d0a91145b53fbf96ac74b0387f6bc51f6 (v4.6.0rc0)
+	NOTE: https://github.com/jupyterlab/jupyterlab/commit/d5d961f6e10a6442dddbf94d9a976b3897055a12 (v4.6.0rc1)
 CVE-2026-67337 (better-auth versions before 1.4.9 contain a two-factor authentication  ...)
 	NOT-FOR-US: Better Auth
 CVE-2026-67336 (better-auth versions before 1.6.11 contain insecure cryptographic defa ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f9bd9777006029e30dbd58ff0f36d76895b0046

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f9bd9777006029e30dbd58ff0f36d76895b0046
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/3c66d56d/attachment.htm>


More information about the debian-security-tracker-commits mailing list