CRITICALPyPI

jupyterlab-git extension: Stored XSS leading to RCE

jupyterlab-git extension: Stored XSS leading to RCE

CVE-2026-54527Published 2 months agoUpdated 2 days agoSource: OSV

Affected packages

  • @jupyterlab/git
  • jupyterlab-git0.30.0b3 → 0.54.0
  • jupyterlab-git-core0.30.0b3 → 0.54.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

jupyterlab-git extension: Stored XSS leading to RCE | HackTribune