jupyterlab-git@0.4.4 vulnerabilities

A JupyterLab extension for version control using git

  • latest version

    0.51.1

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the jupyterlab-git package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Command Injection

    jupyterlab-git is an A JupyterLab extension for version control using git

    Affected versions of this package are vulnerable to Command Injection in the addCommands() function, which executes a cd command on the input passed in to the "Open Git Repository in Terminal" interface. If a user with permission to create a repository names the repository with a malicious string including command substitution - i.e. $(command) they can cause the command to be executed when another user accesses the "Open Git Repository in Terminal" interface.

    How to fix Command Injection?

    Upgrade jupyterlab-git to version 0.51.1 or higher.

    [,0.51.1)