PT-2026-86651 · Undefined · Undefined
CVE-2026-84973
·
Publicado
2026-09-07
·
Atualizado
2026-09-09
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Interesting GitHub Security Lab disclosure: same-second TOCTOU in jupyterlab/maintainer-tools update-snapshots-checkout (CVE-2026-84973).
Race between checkout and snapshot update. Window is measured in the same second the workflow runs.
Classic TOCTOU, but in a maintainer tooling path that many projects inherit.
#AppSec #SupplyChain
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Undefined