CVE-2024-39700

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-39700
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-39700.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-39700
Related
  • GHSA-45gq-v5wm-82wg
Published
2024-07-16T18:15:07Z
Modified
2025-07-02T00:31:28.277918Z
Summary
[none]
Details

JupyterLab extension template is a copier template for JupyterLab extensions. Repositories created using this template with test option include update-integration-tests.yml workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to update-integration-tests.yml, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the main branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.

References

Affected packages

Git / github.com/jupyterlab/extension-template

Affected ranges

Type
GIT
Repo
https://github.com/jupyterlab/extension-template
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v4.*

v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.2.5
v4.2.6
v4.3.0
v4.3.1
v4.3.2