CVE-2026-54527

Source
https://cve.org/CVERecord?id=CVE-2026-54527
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54527.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54527
Aliases
Published
2026-07-08T21:03:01.698Z
Modified
2026-07-17T03:47:46.696470437Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
JupyterLab Git: Stored XSS leading to RCE
Details

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54527.json"
}
References

Affected packages

Git / github.com/jupyterlab/jupyterlab-git

Affected ranges

Type
GIT
Repo
https://github.com/jupyterlab/jupyterlab-git
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": [
        "cpe:2.3:a:jupyter:jupyterlab-git:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:jupyter:jupyterlab-git:0.30.0:-:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0.30.1"
        },
        {
            "fixed": "0.54.0"
        },
        {
            "introduced": "0.30.0-NA"
        },
        {
            "last_affected": "0.30.0-NA"
        }
    ]
}

Affected versions

0.*
0.30.0-NA
v0.*
v0.30.1
v0.31.0
v0.31.0a0
v0.32.0
v0.32.1
v0.32.2
v0.33.0
v0.34.0
v0.34.1
v0.34.2
v0.35.0
v0.36.0
v0.37.0
v0.37.1
v0.38.0
v0.39.0
v0.39.1
v0.39.2
v0.39.3
v0.39.3.post1
v0.40.0
v0.40.1
v0.41.0
v0.42.0
v0.42.0rc0
v0.43.0
v0.44.0
v0.50.0
v0.50.0a0
v0.50.0a1
v0.50.0a2
v0.50.0rc0
v0.50.1
v0.50.2
v0.51.0
v0.51.1
v0.51.2
v0.51.3
v0.51.4
v0.52.0
v0.53.0
v0.53.0a0
v0.53.0a1
v0.54.0a0
v0.54.0a1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54527.json"