This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
Affected surfaces
Summary
AI summaryUpdates Bugs fixed, https://github.com/krassowski, and https://github.com/Yann-P across a mixed release.
Full changelog
4.5.9
Bugs fixed
- Fix
jupyter labextension buildcrash onwebpack ≥ 5.107#19021 (@Darshan808, @krassowski) - Backport PR #18992: Fix hidden cells after moving collapsed headings #19016 (@MUFFANUJ, @krassowski)
- Forbid relative URLs in extensionmanager #19013 (@Yann-P)
- Fix XSS in extension manager's
homepage_url#19003 (@Yann-P) - Fix toolbar popup row clipping in Safari #18998 (@arun-357)
Contributors to this release
The following people contributed discussions, new ideas, code and documentation contributions, and review.
See our definition of contributors.
(GitHub contributors page for this release)
@arun-357 (activity) | @Darshan808 (activity) | @krassowski (activity) | @MUFFANUJ (activity) | @Yann-P (activity)
Security Fixes
- CVE‑2025‑XXXXX — XSS vulnerability fixed in Extension Manager's homepage_url field (GHSA‑xxxxx)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]