VYPR
Critical severity9.0NVD Advisory· Published Jul 8, 2026· Updated Jul 15, 2026

CVE-2026-54527

CVE-2026-54527

Description

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*range: >=0.30.1,<0.54.0
    • cpe:2.3:a:jupyter:jupyterlab-git:0.30.0:-:*:*:*:*:*:*
    • cpe:2.3:a:jupyter:jupyterlab-git:0.30.0:beta3:*:*:*:*:*:*
    • (no CPE)range: <0.54.0

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.