JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:NJupyter Jupyterlab Git
APPJupyter< 0.54.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-54527CRITICAL9.3PL ✓same product
XSS w JupyterLab Git — złośliwa nazwa pliku wykonuje JavaScript
CVE-2026-44181CRITICAL10.0PL ✓same vendor
SSTI w Jupyter Enterprise Gateway umożliwia RCE i przejęcie klastra Kubernetes
CVE-2026-44182CRITICAL10.0PL ✓same vendor
YAML injection w Jupyter Enterprise Gateway — tworzenie uprzywilejowanych podów
CVE-2026-44180CRITICAL9.8PL ✓same vendor
Jupyter Enterprise Gateway — obejście ograniczenia UID/GID i eskalacja do root
CVE-2026-44727CRITICAL9.3PL ✓same vendor
Stored XSS w Jupyter Server umożliwiający RCE przez nbconvert