Back

HIGH

jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories

Published Jul 8, 2026

Description

JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.

Affected products

Remediation

Red Hat statement

This Moderate impact flaw in JupyterLab Git, as deployed in Red Hat OpenShift AI, allows an authenticated user to bypass administrator-defined path exclusions on case-insensitive filesystems. By manipulating the casing of URL path segments, an attacker can gain unauthorized read access to sensitive Git repository information, including file content and commit history, from directories intended to be protected. This bypass occurs because the path enforcement mechanism does not account for filesystem case-insensitivity.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 8, 2026
Updated Jul 9, 2026
Reserved Jun 15, 2026
CISA Vulnrichment
Updated Jul 9, 2026
NVD
Status Analyzed
Modified Jul 15, 2026
Red Hat
Severity Moderate
Public date Jul 8, 2026
GHSA-436Q-JWFR-RM2H