Critical severity9.0NVD Advisory· Published Jul 8, 2026· Updated Jul 15, 2026
CVE-2026-54527
CVE-2026-54527
Description
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*range: >=0.30.1,<0.54.0
- cpe:2.3:a:jupyter:jupyterlab-git:0.30.0:-:*:*:*:*:*:*
- cpe:2.3:a:jupyter:jupyterlab-git:0.30.0:beta3:*:*:*:*:*:*
- (no CPE)range: <0.54.0
Patches
Vulnerability mechanics
References
9- github.com/jupyterlab/jupyterlab-git/commit/c6d37b88f36aa59aee317930b95e427fb9d6b09bnvdPatch
- github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-f962-v9hr-pfg5nvdExploitMitigationVendor Advisory
- github.com/advisories/GHSA-f962-v9hr-pfg5ghsaADVISORY
- github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0nvdRelease Notes
- github.com/pypa/advisory-database/tree/main/vulns/jupyterlab-git-core/PYSEC-2026-2541.yamlghsa
- github.com/pypa/advisory-database/tree/main/vulns/jupyterlab-git/PYSEC-2026-2540.yamlghsa
- nvd.nist.gov/vuln/detail/CVE-2026-54527ghsa
- pypi.org/project/jupyterlab-gitghsa
- pypi.org/project/jupyterlab-git-coreghsa
News mentions
0No linked articles in our index yet.