nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist for users who can not upgrade.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-08-25T18:10:11

Updated: 2024-08-04T01:58:18.218Z

Reserved: 2021-08-16T00:00:00

Link: CVE-2021-39160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-08-25T18:15:08.487

Modified: 2022-10-25T17:51:34.913

Link: CVE-2021-39160

cve-icon Redhat

No data.