CVE-2026-54527
JupyterLab Git: Stored XSS leading to RCE
CVSS Score
0.0
EPSS Score
0.3%
EPSS Percentile
20th
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.
| CWE | CWE-79 |
| Vendor | jupyterlab |
| Product | jupyterlab-git |
| Published | Jul 8, 2026 |
| Last Updated | Jul 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for jupyterlab jupyterlab-git
Be the first to know when new unknown vulnerabilities affecting jupyterlab jupyterlab-git are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
jupyterlab / jupyterlab-git
>= 0.30.0b3, < 0.54.0