VYPR
High severity7.1NVD Advisory· Published Jul 8, 2026· Updated Jul 15, 2026

CVE-2026-54528

CVE-2026-54528

Description

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
jupyterlab-gitPyPI
< 0.54.00.54.0

Affected products

2
  • Jupyter/Jupyterlab Gitllm-fuzzy2 versions
    <0.54.0+ 1 more
    • (no CPE)range: <0.54.0
    • cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*range: <0.54.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.