jupyterlab-git vulnerabilities
CVEs whose affected-version data names the jupyterlab-git package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-54527Highjupyterlab-git extension: Stored XSS leading to RCE
jupyterlab-git extension: Stored XSS leading to RCE
▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.53%via GHSA
CVE-2026-54528High· 7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.41%via GHSA
CVE-2025-30370High· 7.4jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
▾ Twilightjupyterlab-git · jupyterlab-gitEPSS 0.58%via OSV