pypi package report

Is jupyterlab-git safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.1

how bad it is if exploited, out of 10

epss
0.40%

chance of exploitation in the next 30 days

xyz score
3.9

CyberXYZ composite, out of 10

fig. 01 — GHSA-436q-jwfr-rm2h, the advisory selected below

// advisories

GHSA-436q-jwfr-rm2h

HIGHCVE-2026-54528

jupyterlab-git 0.53.0 (latest, 2026-04-30) uses fnmatch.fnmatchcase() in GitHandler.prepare() (jupyterlabgit/handlers.py:91) to enforce the admin-configured excludedpaths security control. Because fnmatchcase is unconditionally case-sensitive, an authenticated user on a case-insensitive filesystem (macOS APFS, Windows NTFS) can bypass the exclusion by varying the case of the URL path segment — e.g

Affected
<= 0.53.0
Fixed in
0.54.0
Weakness
CWE-178
Published
2026-06-19
Source
github

GHSANVDMITREreference


// dependencies

4 direct, 1 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2026-06-19. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is jupyterlab-git safe? pypi package security report | CyberXYZ