CVE-2026-54528

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*

History

15 Jul 2026, 20:42

Type Values Removed Values Added
CPE cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*
First Time Jupyter jupyterlab-git
Jupyter
References () https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033 - () https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033 - Patch
References () https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0 - () https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0 - Release Notes
References () https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h - () https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h - Exploit, Vendor Advisory

09 Jul 2026, 14:16

Type Values Removed Values Added
References () https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h - () https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h -

08 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-08 21:16

Updated : 2026-07-15 20:42


NVD link : CVE-2026-54528

Mitre link : CVE-2026-54528

CVE.ORG link : CVE-2026-54528


JSON object : View

Products Affected

jupyter

  • jupyterlab-git
CWE
CWE-178

Improper Handling of Case Sensitivity