Showing 1 vulnerability on this page for extension-template

Signals CISA KEV Ransomware Nuclei
jupyter vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions

CWE-94Jul 16, 2024
CVSS10.0v3.1EPSS1.02%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX