CVE-2025-30370: jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"

Published Apr 3, 2025
·
Updated

Overview

On many platforms, a third party can create a Git repository under a name that includes a shell command substitution [^1] string in the syntax $(<command>). These directory names are allowed in macOS and a majority of Linux distributions [^2]. If a user starts jupyter-lab in a parent directory of this inappropriately-named Git repository, opens it, and clicks "Git > Open Git Repository in Terminal" from the menu bar, then the injected command <command> is run in the user's shell without the user's permission.

This issue is occurring because when that menu entry is clicked, jupyterlab-git opens the terminal and runs cd <git-repo-path> through the shell to set the current directory [^3]. Doing so runs any command substitution strings present in the directory name, which leads to the command injection issue described here. A previous patch provided an incomplete fix [^4].

[^1]: https://www.gnu.org/software/bash/manual/htmlnode/Command-Substitution.html [^2]: https://www.gnu.org/software/libc/manual/htmlnode/File-Name-Portability.html [^3]: https://github.com/jupyterlab/jupyterlab-git/blob/7eb3b06f0092223bd5494688ec264527bbeb2195/src/commandsAndMenu.tsx#L175-L184 [^4]: https://github.com/jupyterlab/jupyterlab-git/pull/1196

Scope of Impact

This issue allows for arbitrary code execution via command injection. A wide range of actions are permitted by this issue, including but not limited to: modifying files, exfiltrating data, halting services, or compromising the server's security rules.

We have scanned the source code of jupyterlab-git for other command injection risks, and have not found any at the time of writing.

This issue was reproduced on the latest release of jupyterlab-git, v0.51.0. The steps taken to reproduce this issue are described in the "Proof-of-concept" section below.

Proof-of-concept

1. Create a new directory via mkdir test/ && cd test/.

2. Create a new Git repository under test/ with a command substitution string in the directory name by running these commands:

mkdir '$(touch pwned.txt)' cd '$(touch pwned.txt)/' git init cd ..

3. Start JupyterLab from test/ by running jupyter lab. 4. With JupyterLab open in the browser, double click on $(touch pwned.txt) in the file browser. 5. From the top menu bar, click "Git > Open Git Repository in Terminal". 6. Verify that pwned.txt is created under test/. This demonstrates the command injection issue described here.

Proof-of-concept mitigation

The issue can be mitigated by the patch shown below.

<details><summary>Patch (click to expand)</summary>

diff diff --git a/src/commandsAndMenu.tsx b/src/commandsAndMenu.tsx index 3779a6c..71ddcea 100644 --- a/src/commandsAndMenu.tsx +++ b/src/commandsAndMenu.tsx @@ -164,31 +164,13 @@ export function addCommands( label: trans.('Open Git Repository in Terminal'), caption: trans.('Open a New Terminal to the Git Repository'), execute: async args => { - const main = (await commands.execute( - 'terminal:create-new', - args - )) as MainAreaWidget<ITerminal.ITerminal>; + const cwd = gitModel.pathRepository; + const main = (await commands.execute('terminal:create-new', { + ...args, + cwd + })) as MainAreaWidget<ITerminal.ITerminal>; - try { - if (gitModel.pathRepository !== null) { - const terminal = main.content; - terminal.session.send({ - type: 'stdin', - content: [ - cd "${gitModel.pathRepository - .split('"') - .join('\\"') - .split('') - .join('\\')}"\n - ] - }); - } - - return main; - } catch (e) { - console.error(e); - main.dispose(); - } + return main; </details>

This patch removes the cd <git-repo-path> shell command that causes the issue. To preserve the existing behavior, the cwd argument is set to <git-repo-path> when a terminal session is created via the terminal:create-new JupyterLab command. This preserves the existing application behavior while mitigating the command injection issue.

We have verified that this patch works when applied to a local installation of jupyterlab-git. We have also verified that the cwd argument is available in all versions of JupyterLab 4, so this patch should be fully backwards-compatible.

Workarounds

We recommend that users upgrade to the patched versions listed on this GHSA. However, if a user is unable to upgrade, there are 3 different ways to mitigate this vulnerability without upgrading to a patch.

1. Disable terminals on jupyter-server level: c.ServerApp.terminalsenabled = False

2. Disable the terminals server extension: jupyter server extension disable jupyterserverterminals

3. Disable the lab extension: jupyter labextension disable @jupyterlab/terminal-extension

Other sources

jupyterlab-git is a JupyterLab extension for version control using Git. On many platforms, a third party can create a Git repository under a name that includes a shell command substitution string in the syntax $(<command>). These directory names are allowed in macOS and a majority of Linux distributions. If a user starts jupyter-lab in a parent directory of this inappropriately-named Git repository, opens it, and clicks "Git > Open Git Repository in Terminal" from the menu bar, then the injected command <command> is run in the user's shell without the user's permission. This issue is occurring because when that menu entry is clicked, jupyterlab-git opens the terminal and runs cd <git-repo-path> through the shell to set the current directory. Doing so runs any command substitution strings present in the directory name, which leads to the command injection issue described here. A previous patch provided an incomplete fix. This vulnerability is fixed in 0.51.1.

MITRE

Affected Software

2 affected componentsFixes available
Project Jupyter jupyterlab-git<0.51.1
pip/jupyterlab-git<0.51.1
0.51.1

Event History

Apr 3, 2025
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Apr 4, 2025
Advisory Published
via GitHub·02:05 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-30370?

CVE-2025-30370 has been assigned a high severity rating due to its potential for arbitrary command execution through crafted Git repository names.

2

How do I fix CVE-2025-30370?

To fix CVE-2025-30370, update jupyterlab-git to version 0.51.1 or later.

3

What platforms are affected by CVE-2025-30370?

CVE-2025-30370 primarily affects macOS along with a majority of other platforms that allow shell command substitution in Git repository names.

4

What does CVE-2025-30370 exploit?

CVE-2025-30370 exploits the ability of third parties to create Git repositories with names that include shell command substitution segments.

5

Is there a workaround for CVE-2025-30370?

A temporary workaround for CVE-2025-30370 is to avoid using Git repository names that include shell command substitution patterns.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203