[Git][security-tracker-team/security-tracker][master] Add two jupyterlab issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 22:16:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cbfe4af6 by Salvatore Bonaccorso at 2026-08-14T23:15:55+02:00
Add two jupyterlab issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -362,9 +362,13 @@ CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
 	NOT-FOR-US: Next.js
 CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	TODO: check
+	- jupyterlab <unfixed>
+	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
+	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
-	TODO: check
+	- jupyterlab <unfixed>
+	NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8
+	NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
 CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
 	NOT-FOR-US: Budibase
 CVE-2026-73305 (Budibase is an open-source low-code platform. Prior to 3.39.24, POST / ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbfe4af6af2f5f7a95b8b1d6fd9384a4cf35b5b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cbfe4af6af2f5f7a95b8b1d6fd9384a4cf35b5b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/21293bd3/attachment.htm>


More information about the debian-security-tracker-commits mailing list