HIGH🇵🇱 Wersja polska

CVE-2026-54528

CVSS 7.1v3.1pub. 2026-07-08upd. 2026-07-15

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  • Jupyter Jupyterlab Git

    APP
    Jupyter
    < 0.54.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-54527CRITICAL9.3PL ✓same product

XSS w JupyterLab Git — złośliwa nazwa pliku wykonuje JavaScript

CVE-2026-44181CRITICAL10.0PL ✓same vendor

SSTI w Jupyter Enterprise Gateway umożliwia RCE i przejęcie klastra Kubernetes

CVE-2026-44182CRITICAL10.0PL ✓same vendor

YAML injection w Jupyter Enterprise Gateway — tworzenie uprzywilejowanych podów

CVE-2026-44180CRITICAL9.8PL ✓same vendor

Jupyter Enterprise Gateway — obejście ograniczenia UID/GID i eskalacja do root

CVE-2026-44727CRITICAL9.3PL ✓same vendor

Stored XSS w Jupyter Server umożliwiający RCE przez nbconvert