PT-2026-86651 · Undefined · Undefined

CVE-2026-84973

·

Publicado

2026-09-07

·

Atualizado

2026-09-09

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Interesting GitHub Security Lab disclosure: same-second TOCTOU in jupyterlab/maintainer-tools update-snapshots-checkout (CVE-2026-84973).
Race between checkout and snapshot update. Window is measured in the same second the workflow runs.
Classic TOCTOU, but in a maintainer tooling path that many projects inherit.
#AppSec #SupplyChain
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-84973

Produtos afetados

Undefined