[Git][security-tracker-team/security-tracker][master] Add CVE-2026-73415/jupyterlab
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 07:34:10 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
76e9c3ca by Salvatore Bonaccorso at 2026-08-14T08:33:51+02:00
Add CVE-2026-73415/jupyterlab
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1078,7 +1078,10 @@ CVE-2026-73419 (NextAuth.js provides authentication for Next.js. Prior to at auth/c
CVE-2026-73418 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
NOT-FOR-US: Next.js
CVE-2026-73415 (jupyterlab is an extensible environment for interactive and reproducib ...)
- TODO: check
+ - jupyterlab <unfixed>
+ NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-gx64-gj6p-pc4c
+ NOTE: https://github.com/jupyterlab/jupyterlab/pull/19186
+ NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73414 (Shescape is a simple shell escape library for JavaScript. Prior to 2.1 ...)
NOT-FOR-US: Shescape
CVE-2026-73413 (Shescape is a simple shell escape library for JavaScript. From 2.1.11 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76e9c3cac717b29efb65019a39364951fe6799a7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/76e9c3cac717b29efb65019a39364951fe6799a7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/27d138da/attachment.htm>
More information about the debian-security-tracker-commits
mailing list