Critical severity9.6NVD Advisory· Published Aug 25, 2021· Updated Jun 17, 2026
CVE-2021-39160
CVE-2021-39160
Description
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist for users who can not upgrade.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nbgitpullerPyPI | >= 0.9.0, < 0.10.2 | 0.10.2 |
Affected products
3- jupyterhub/nbgitpullerv5Range: >= 0.9.0, < 0.10.2
Patches
Vulnerability mechanics
References
6- github.com/jupyterhub/nbgitpuller/commit/07690644f29a566011dd0d7ba14cae3eb0490481nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mq5p-2mcr-m52jghsaADVISORY
- github.com/jupyterhub/nbgitpuller/blob/main/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- github.com/jupyterhub/nbgitpuller/security/advisories/GHSA-mq5p-2mcr-m52jnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-39160ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/nbgitpuller/PYSEC-2021-315.yamlghsaWEB
News mentions
0No linked articles in our index yet.