#cwe-84

共收录 5 条相关安全情报。

← 返回所有主题

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Secondary 数据源 (+2) | 包含 CVE (+2) | LLM 评分加成 (+0.4)
CVE-2026-67338

JupyterLab 在 4.5.9 之前的版本中,扩展管理器存在一个存储型跨站脚本(XSS)漏洞。该漏洞源于扩展管理器在解析包元数据 URL 时未能验证 URI 协议。攻击者可以在 PyPI 上发布恶意的 Python 包,在项目元数据中嵌入 javascript: 协议的 URL。当用户点击扩展名称时,恶意 URL 会触发任意 JavaScript 代码在 JupyterLab 的源环境中执行。由于 JupyterLab 通常运行在本地回环地址并拥有较高的用户权限,攻击者可能通过此漏洞窃取用户的会话凭证、访问令牌,或修改用户的笔记本文件。该漏洞的 CVSS 评分为 6.1(中等),攻击复杂度低,需要用户交互,但可造成机密性和完整性的轻微损失。目前没有证据表明该漏洞已被在野利用,也未列入已知被利用漏洞(KEV)清单。建议用户尽快升级至 JupyterLab 4.5.9 或更高版本,并考虑限制扩展管理器的网络访问,避免安装来源不明的扩展包。

💡 影响/原因: JupyterLab 是数据科学和学术领域广泛使用的交互式开发环境,存储型 XSS 可导致任意代码执行,直接影响用户数据和实验环境,且漏洞利用门槛低,潜在影响面大。

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)
推荐 8.4
Conf: 50%

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can publish malicious PyPI packages with javascript: URLs in project metadata that execute arbitrary JavaScript in the JupyterLab origin when users click the extension name.

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | 包含 CVE (+2) | LLM 评分加成 (+0.4)
CVE-2026-54443

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

💡 影响/原因: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: Primary 数据源 (+3) | LLM 评分加成 (+0.4)

Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssFeed.vue does not sanitize RSS item link values before rendering feed item titles and Read More links as anchor href attributes, allowing an attacker-controlled feed to provide a javascript: URI that executes when clicked in the Dashy origin. This issue is fixed in version 3.2.0.

💡 风险点: 原文内容(由于配额限制,未进行深度 LLM 分析)

🎯 建议动作: 建议根据原文自行评估

排序因子: 有可用补丁/修复方案 (+3) | Primary 数据源 (+3) | 包含 CVE (+2) | LLM 评分加成 (+0.4)