CVE-2026-54527
Critical · CVSS 9.3jupyterlab-git — Stored Cross-Site Scripting (XSS) via unsanitized innerHTML injection
- CVSS
- 9.3
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-79
Description
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.
Search profile — drives PoC discovery
Symbols PlainTextDiff.tscreateHeaderinnerHTMLjupyterlab-git@jupyterlab/gitjupyterlab-git-corePlainTextDiffGit History tabrename diff
Keywords CVE-2026-54527GHSA-f962-v9hr-pfg5jupyterlab-git XSSPlainTextDiff createHeader innerHTMLjupyterlab git filename XSSjupyterlab git rename diff XSSjupyterlab git commit history XSSjupyterlab-git proof of conceptjupyterlab-git PoC exploit
Versions: 0.30.0b3 <= version < 0.54.0
Affected packages
| PyPI | jupyterlab-git | 0.30.0b3 → 0.54.0 |
| PyPI | jupyterlab-git-core | 0.30.0b3 → 0.54.0 |
| npm | @jupyterlab/git | 0.30.0b3 → 0.54.0 |
References
- https://github.com/jupyterlab/jupyterlab-git/commit/c6d37b88f36aa59aee317930b95e427fb9d6b09b
- https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0
- https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-f962-v9hr-pfg5
- https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-f962-v9hr-pfg5
Status: enriched · ingested 2026-07-11T00:00:26.000Z · profiled 2026-07-11T00:30:26.000Z