CVEFinder.io

CVE-2025-59842

🔶 medium
🔍 Scan for this CVE
Summary

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the noopener attribute. This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if links

Description

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4.4.8, links generated with LaTeX typesetters in Markdown files and Markdown cells in JupyterLab and Jupyter Notebook did not include the noopener attribute. This is deemed to have no impact on the default installations. Theoretically users of third-party LaTeX-rendering extensions could find themselves vulnerable to reverse tabnabbing attacks if links generated by those extensions included target=_blank (no such extensions are known at time of writing) and they were to click on a link generated in LaTeX (typically visibly different from other links). This issue has been patched in version 4.4.8.

CVSS Score
4.3
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2025-09-26
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 5.4% of all 328,009 vulnerabilities in our database.

#310,261
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Sep 26, 2025
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-10-22
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-42266 ⚠️ high 8.8 0.0 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... 2026-05-13
CVE-2026-42557 ⛔ critical 9.6 0.1 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... 2026-05-13
CVE-2024-43805 ⚠️ high 7.6 0.4 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... 2024-08-28
CVE-2024-39700 ⛔ critical 9.9 3.9 JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this templat... 2024-07-16
CVE-2024-22420 🔶 medium 6.5 0.5 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Ar... 2024-01-19
CVE-2024-22421 ⚠️ high 7.6 0.1 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Ar... 2024-01-19
These CVEs affect the same products