A review workflow for Jupyter notebooks became a potential server-side execution path, showing how one untrusted file format can become dangerous when a native parser sits in the middle.
A published proof-of-concept shows how a normal project account, two crafted Jupyter notebooks, and a diff request can turn a review feature into command execution as the Git service user.