Stored XSS to RCE in jupyterlab-git (CVE-2026-54327) with POC
Security Advisory
CVE-2026-54327
Critical
Jupyter
Affected:
- @jupyterlab/git>=0.30.0b3, <0.54.0-a1
- jupyterlab-git>=0.30.0b3, <0.54.0a1
- jupyterlab-git-core>=0.30.0b3, <0.54.0a1
Fixed in:
- @jupyterlab/git@0.54.0
- jupyterlab-git@0.54.0
- jupyterlab-git-core@0.54.0
Referenced CVEs:
CVE-2026-54527
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.