PT-2024-28639 · Unknown+1 · Jupyterlab Extension Template+1
Avivkeller
+1
·
Published
2024-07-16
·
Updated
2025-12-18
·
CVE-2024-39700
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JupyterLab extension template versions prior to 4.3.0
Description
The JupyterLab extension template has a remote code execution (RCE) vulnerability in the
update-integration-tests.yml workflow. This issue affects repositories created using the template with the test option. Extension authors are advised to upgrade the template to the latest version. Users who have modified the update-integration-tests.yml file should accept overwriting of this file and reapply their changes later. It is recommended to temporarily disable GitHub Actions while working on the upgrade and to rebase all open pull requests from untrusted users.Recommendations
For versions prior to 4.3.0, upgrade the template to the latest version, overwriting the
update-integration-tests.yml file if necessary, and reapply any changes made to this file later.
As a temporary workaround, consider disabling GitHub Actions until the upgrade is complete.
Restrict access to untrusted users' pull requests and rebase them to ensure actions run with the updated version.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Jupyterlab Extension Template