CVE-2026-54528

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-08 21:16

Updated : 2026-07-15 20:42


NVD link : CVE-2026-54528

Mitre link : CVE-2026-54528

CVE.ORG link : CVE-2026-54528


JSON object : View

Products Affected

jupyter

  • jupyterlab-git
CWE
CWE-178

Improper Handling of Case Sensitivity