CVE-2026-102831 JupyterLab 剪贴板粘贴信任绕过漏洞
影响攻击者可绕过输出净化在已认证源执行脚本
JupyterLab 是基于 Jupyter Notebook 架构的可扩展交互式计算环境。在特定版本中,系统剪贴板单元格粘贴路径会接受攻击者可控的单元格 JSON 且未清除 metadata.trusted 标记。当启用 useSystemClipboardForCells 且禁用 pasteCodeCellsWithoutOutput 时,粘贴的代码单元格可将 HTML 输出标记为受信任,从而绕过输出净化并在已认证的 JupyterLab 源中执行脚本。
影响范围
受影响范围包括 JupyterLab 4.5.0 至 4.5.11 之前、4.6.4 之前,Notebook 7.5.0 至 7.6.3 之前,以及 JupyterLite Core 0.7.0 至 0.8.4 之前。修复版本为 JupyterLab 4.5.11 和 4.6.4、Notebook 7.6.3、JupyterLite Core 0.8.4。
漏洞详情
漏洞类型为信任标记绕过导致的跨站脚本(XSS)。成因是系统剪贴板粘贴单元格时未清除 metadata.trusted 字段,使攻击者构造的单元格 JSON 被当作可信内容处理。利用方式是诱导用户粘贴恶意单元格,其 HTML 输出绕过净化并在已认证源中执行脚本,且无需实际执行该单元格。Markdown 和 raw 单元格因输出经过净化而不受影响。
利用条件与风险
利用前提是目标启用了 useSystemClipboardForCells 且禁用了 pasteCodeCellsWithoutOutput,并需诱导用户执行粘贴操作。实战中可导致在已认证会话上下文中执行脚本,风险较高。
修复建议
官方已在 JupyterLab 4.5.11 和 4.6.4、Notebook 7.6.3、JupyterLite Core 0.8.4 中修复,建议尽快升级。临时缓解措施为禁用 useSystemClipboardForCells 或启用 pasteCodeCellsWithoutOutput,具体配置方式暂无公开信息。
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, bypass output sanitization, and execute script in the authenticated JupyterLab origin without executing the cell. Markdown and raw cells are not affected because their output is sanitized. This issue is fixed in JupyterLab 4.5.11 and 4.6.4, Notebook 7.6.3, and JupyterLite Core 0.8.4.