Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54528

Опубликовано: 08 июл. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*
Версия до 0.54.0 (исключая)

EPSS

Процентиль: 28%
0.0035
Низкий

7.1 High

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 6.5
redhat
27 дней назад

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.

CVSS3: 7.1
github
около 2 месяцев назад

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

EPSS

Процентиль: 28%
0.0035
Низкий

7.1 High

CVSS3

Дефекты

CWE-178