Understanding the JupyterLab Image Viewer XSS Vulnerability
This educational analysis covers a critical vulnerability in JupyterLab's image viewer, allowing cross-site scripting (XSS) when a specially-crafted image file is opened and then viewed in a new browser tab. This can lead to remote code execution (RCE) on the JupyterLab server. The vulnerability is addressed in JupyterLab versions 4.6.2 and 4.5.10.