Command Injection Vulnerability in JupyterLab Git Extension by Jupyter
CVE-2025-30370
What is CVE-2025-30370?
The jupyterlab-git extension for JupyterLab is vulnerable to a command injection issue due to the improper handling of directory names that contain shell command substitution strings. This vulnerability allows unauthorized execution of commands when a user interacts with the Git repository feature, potentially compromising the user's shell environment. This happens when the terminal is opened in a parent directory of a maliciously named Git repository. An incomplete fix has previously been issued, but the latest version 0.51.1 addresses this critical security concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
jupyterlab-git < 0.51.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
