Tuesday 28 July 2026 18:38:37 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Jupyter Notebook


GitLab’s Notebook Feature Exposed a Hidden Parser Trap

Published: 27 July 2026 08:31Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A review workflow for Jupyter notebooks became a potential server-side execution path, showing how one untrusted file format can become dangerous when a native parser sits in the middle.

GitLab Notebook Diffs Become an RCE Trigger in a New Authenticated-User PoC

Published: 25 July 2026 12:06Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: DEBUGSAGE

A published proof-of-concept shows how a normal project account, two crafted Jupyter notebooks, and a diff request can turn a review feature into command execution as the Git service user.