[GHSA-37w4-hwhx-4rc4] JupyterHub has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request #6587
Triggered via pull request
May 21, 2026 00:41
advisory-database[bot]
closed
#7593
Status
Failure
Total duration
1m 5s
Artifacts
–
delete_staging_and_head_branches.yaml
on: pull_request_target
delete-staging-and-head-branches
1m 2s
Annotations
1 error
|
delete-staging-and-head-branches
Process completed with exit code 1.
|