CVE-2026-54527: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jupyterlab jupyterlab-git
A critical cross-site scripting (XSS) vulnerability exists in jupyterlab-git versions before 0.54.0. The vulnerability arises because the PlainTextDiff.ts createHeader() method improperly passes Git filenames directly to innerHTML when rendering renamed files in the Git History tab. This allows an attacker to craft a malicious filename that executes JavaScript code when viewed. The issue is fixed in version 0.54.0.
AI Analysis
Technical Summary
CVE-2026-54527 is a CWE-79 (Improper Neutralization of Input During Web Page Generation) vulnerability affecting jupyterlab-git, a Git extension for JupyterLab. Specifically, in versions from 0.30.0b3 up to but not including 0.54.0, the createHeader() method in PlainTextDiff.ts inserts Git filenames directly into innerHTML without sanitization when rendering renamed files in the commit history. This improper handling allows an attacker to execute arbitrary JavaScript code when a user views the rename diff in the Git History tab. The vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity. The issue is resolved in version 0.54.0.
Potential Impact
An attacker can exploit this vulnerability by crafting a malicious Git filename that, when viewed in the Git History tab of jupyterlab-git, executes arbitrary JavaScript code in the context of the victim's browser. This can lead to actions such as session hijacking, data theft, or other malicious behaviors depending on the victim's privileges and environment. The vulnerability requires user interaction (viewing the rename diff) and low attack complexity, with no privileges required but user interaction needed. The impact on confidentiality, integrity, and availability is high.
Mitigation Recommendations
This vulnerability is fixed in jupyterlab-git version 0.54.0. Users and administrators should upgrade to version 0.54.0 or later to remediate this issue. No other official remediation or temporary fixes are documented. Until upgrading, avoid viewing rename diffs from untrusted repositories or filenames.
CVE-2026-54527: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in jupyterlab jupyterlab-git
Description
A critical cross-site scripting (XSS) vulnerability exists in jupyterlab-git versions before 0.54.0. The vulnerability arises because the PlainTextDiff.ts createHeader() method improperly passes Git filenames directly to innerHTML when rendering renamed files in the Git History tab. This allows an attacker to craft a malicious filename that executes JavaScript code when viewed. The issue is fixed in version 0.54.0.
CVSS v4.0
Score 9.3critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-54527 is a CWE-79 (Improper Neutralization of Input During Web Page Generation) vulnerability affecting jupyterlab-git, a Git extension for JupyterLab. Specifically, in versions from 0.30.0b3 up to but not including 0.54.0, the createHeader() method in PlainTextDiff.ts inserts Git filenames directly into innerHTML without sanitization when rendering renamed files in the commit history. This improper handling allows an attacker to execute arbitrary JavaScript code when a user views the rename diff in the Git History tab. The vulnerability has a CVSS 4.0 base score of 9.3, indicating critical severity. The issue is resolved in version 0.54.0.
Potential Impact
An attacker can exploit this vulnerability by crafting a malicious Git filename that, when viewed in the Git History tab of jupyterlab-git, executes arbitrary JavaScript code in the context of the victim's browser. This can lead to actions such as session hijacking, data theft, or other malicious behaviors depending on the victim's privileges and environment. The vulnerability requires user interaction (viewing the rename diff) and low attack complexity, with no privileges required but user interaction needed. The impact on confidentiality, integrity, and availability is high.
Mitigation Recommendations
This vulnerability is fixed in jupyterlab-git version 0.54.0. Users and administrators should upgrade to version 0.54.0 or later to remediate this issue. No other official remediation or temporary fixes are documented. Until upgrading, avoid viewing rename diffs from untrusted repositories or filenames.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T18:40:01.651Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4ebdf5c9d9e3dbe3bf8b00
Added to database: 07/08/2026, 21:15:33 UTC
Last enriched: 07/16/2026, 10:11:07 UTC
Last updated: 07/16/2026, 23:21:50 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.