jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
Published Jul 8, 2026
7.1
HIGHCVSS 3.1
EPSS 0.41%
Description
JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandler.prepare() in jupyterlab_git/handlers.py to enforce excluded_paths, allowing an authenticated user on a case-insensitive filesystem to vary URL path casing and read excluded directories. This issue is fixed in version 0.54.0.
Affected products
-
- Version < 0.54.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Jupyterlab | Jupyterlab-Git | n/a |
|
- < 0.54.0
No data.
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cpu-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch210-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-cuda130-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-th06-rocm64-torch291-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cpu-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch210-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-cuda130-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-th06-rocm64-torch291-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact flaw in JupyterLab Git, as deployed in Red Hat OpenShift AI, allows an authenticated user to bypass administrator-defined path exclusions on case-insensitive filesystems. By manipulating the casing of URL path segments, an attacker can gain unauthorized read access to sensitive Git repository information, including file content and commit history, from directories intended to be protected. This bypass occurs because the path enforcement mechanism does not account for filesystem case-insensitivity.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-54528 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2498291 Issue Tracking
- https://github.com/advisories/GHSA-436q-jwfr-rm2h Advisory
- https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033 x_refsource_MISCPatch
- https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0 x_refsource_MISCRelease Notes
- https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54528
- https://www.cve.org/CVERecord?id=CVE-2026-54528
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-54528 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2498291 | Issue Tracking | |
| https://github.com/advisories/GHSA-436q-jwfr-rm2h | Advisory | |
| https://github.com/jupyterlab/jupyterlab-git/commit/460035275b5963dc96e364e60ba6a73717fbd033 | x_refsource_MISCPatch | |
| https://github.com/jupyterlab/jupyterlab-git/releases/tag/v0.54.0 | x_refsource_MISCRelease Notes | |
| https://github.com/jupyterlab/jupyterlab-git/security/advisories/GHSA-436q-jwfr-rm2h | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-54528 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-54528 |
Change history (0)
No recorded changes yet.