CVE-2026-54528
גבוהה 7.1
תיאור (מקור, אנגלית)
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
מדדים
- CVSS 3.1
-
7.1 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-17/8/2026
- CWE
- CWE-178
מוצרים מושפעים
jupyter: jupyterlab-git
קישורים
- https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwf… ExploitVendor Advisory
- https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwf… ExploitVendor Advisory
- https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60b… Patch
- https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0 Release Notes