<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:11:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335326</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335326</link>
      <description>EUVD-2026-335326</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335326</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54527</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54527</link>
      <description>&lt;p&gt;JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54527</guid>
    </item>
    <item>
      <title>GHSA-f962-v9hr-pfg5 — jupyterlab-git extension: Stored XSS leading to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f962-v9hr-pfg5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterlab-git, PyPI: jupyterlab-git-core, npm: @jupyterlab/git&lt;/p&gt;
&lt;p&gt;Overview&lt;/p&gt;
&lt;p&gt;Amazon Web Services (AWS) Security has identified a stored cross-site scripting (XSS) issue in the jupyterlab-git JupyterLab extension that can lead to remote code execution (RCE). The issue exists in the PlainTextDiff.ts component, where the createHeader() method passes Git filenames directly to innerHTML without sanitization when rendering diffs for renamed files in commit history. This allows an adversary to craft a filename containing arbitrary HTML/JavaScript that executes when another user views the rename diff in the Git History tab.&lt;/p&gt;
&lt;p&gt;The issue can be leveraged through the rename history view in the JupyterLab Git panel. An adversary creates a file with a crafted filename containing a JavaScript payload (e.g., &amp;lt;img src=x onerror=eval(atob(&amp;#34;base64_payload&amp;#34;))&amp;gt;.py), renames the file in a subsequent commit, and pushes to a shared repository. When a victim clones the repository, navigates to the Git History tab, clicks the rename commit, and then clicks the renamed file to view the diff, the unsanitized filename renders via innerHTML, executing arbitrary JavaScript in the victim&amp;#39;s browser session. The injected JavaScript reads the xsrf cookie, opens a JupyterLab terminal via POST /api/terminals, connects via WebSocket, and executes arbitrary shell commands — achieving full RCE. An adversary can leverage this to exfiltrate secrets or credentials from the victim&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Scope of impact&lt;/p&gt;
&lt;p&gt;We discovered this issue during internal security testing. The issue…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterlab-git, PyPI: jupyterlab-git-core, npm: @jupyterlab/git&lt;/p&gt;
&lt;p&gt;Overview&lt;/p&gt;
&lt;p&gt;Amazon Web Services (AWS) Security has identified a stored cross-site scripting (XSS) issue in the jupyterlab-git JupyterLab extension that can lead to remote code execution (RCE). The issue exists in the PlainTextDiff.ts component, where the createHeader() method passes Git filenames directly to innerHTML without sanitization when rendering diffs for renamed files in commit history. This allows an adversary to craft a filename containing arbitrary HTML/JavaScript that executes when another user views the rename diff in the Git History tab.&lt;/p&gt;
&lt;p&gt;The issue can be leveraged through the rename history view in the JupyterLab Git panel. An adversary creates a file with a crafted filename containing a JavaScript payload (e.g., &amp;lt;img src=x onerror=eval(atob(&amp;#34;base64_payload&amp;#34;))&amp;gt;.py), renames the file in a subsequent commit, and pushes to a shared repository. When a victim clones the repository, navigates to the Git History tab, clicks the rename commit, and then clicks the renamed file to view the diff, the unsanitized filename renders via innerHTML, executing arbitrary JavaScript in the victim&amp;#39;s browser session. The injected JavaScript reads the xsrf cookie, opens a JupyterLab terminal via POST /api/terminals, connects via WebSocket, and executes arbitrary shell commands — achieving full RCE. An adversary can leverage this to exfiltrate secrets or credentials from the victim&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Scope of impact&lt;/p&gt;
&lt;p&gt;We discovered this issue during internal security testing. The issue…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f962-v9hr-pfg5</guid>
    </item>
    <item>
      <title>PYSEC-2026-2540 — jupyterlab-git extension: Stored XSS leading to RCE</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2540</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterlab-git&lt;/p&gt;
&lt;p&gt;Overview&lt;/p&gt;
&lt;p&gt;Amazon Web Services (AWS) Security has identified a stored cross-site scripting (XSS) issue in the jupyterlab-git JupyterLab extension that can lead to remote code execution (RCE). The issue exists in the PlainTextDiff.ts component, where the createHeader() method passes Git filenames directly to innerHTML without sanitization when rendering diffs for renamed files in commit history. This allows an adversary to craft a filename containing arbitrary HTML/JavaScript that executes when another user views the rename diff in the Git History tab.&lt;/p&gt;
&lt;p&gt;The issue can be leveraged through the rename history view in the JupyterLab Git panel. An adversary creates a file with a crafted filename containing a JavaScript payload (e.g., &amp;lt;img src=x onerror=eval(atob(&amp;#34;base64_payload&amp;#34;))&amp;gt;.py), renames the file in a subsequent commit, and pushes to a shared repository. When a victim clones the repository, navigates to the Git History tab, clicks the rename commit, and then clicks the renamed file to view the diff, the unsanitized filename renders via innerHTML, executing arbitrary JavaScript in the victim&amp;#39;s browser session. The injected JavaScript reads the xsrf cookie, opens a JupyterLab terminal via POST /api/terminals, connects via WebSocket, and executes arbitrary shell commands — achieving full RCE. An adversary can leverage this to exfiltrate secrets or credentials from the victim&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Scope of impact&lt;/p&gt;
&lt;p&gt;We discovered this issue during internal security testing. The issue…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyterlab-git&lt;/p&gt;
&lt;p&gt;Overview&lt;/p&gt;
&lt;p&gt;Amazon Web Services (AWS) Security has identified a stored cross-site scripting (XSS) issue in the jupyterlab-git JupyterLab extension that can lead to remote code execution (RCE). The issue exists in the PlainTextDiff.ts component, where the createHeader() method passes Git filenames directly to innerHTML without sanitization when rendering diffs for renamed files in commit history. This allows an adversary to craft a filename containing arbitrary HTML/JavaScript that executes when another user views the rename diff in the Git History tab.&lt;/p&gt;
&lt;p&gt;The issue can be leveraged through the rename history view in the JupyterLab Git panel. An adversary creates a file with a crafted filename containing a JavaScript payload (e.g., &amp;lt;img src=x onerror=eval(atob(&amp;#34;base64_payload&amp;#34;))&amp;gt;.py), renames the file in a subsequent commit, and pushes to a shared repository. When a victim clones the repository, navigates to the Git History tab, clicks the rename commit, and then clicks the renamed file to view the diff, the unsanitized filename renders via innerHTML, executing arbitrary JavaScript in the victim&amp;#39;s browser session. The injected JavaScript reads the xsrf cookie, opens a JupyterLab terminal via POST /api/terminals, connects via WebSocket, and executes arbitrary shell commands — achieving full RCE. An adversary can leverage this to exfiltrate secrets or credentials from the victim&amp;#39;s environment.&lt;/p&gt;
&lt;p&gt;Scope of impact&lt;/p&gt;
&lt;p&gt;We discovered this issue during internal security testing. The issue…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2540</guid>
    </item>
  </channel>
</rss>
