Published September 4, 2026 ยท Added September 8, 2026

GHSL-2026-203: Same-second TOCTOU vulnerability in jupyterlab/maintainer-tools update-snapshots-checkout - CVE-2026-84973

GitHub Security Lab lists this Jupyter maintainer-tools advisory among vulnerabilities discovered with AI agents: a same-second race in update-snapshots-checkout could let an attacker make a privileged workflow check out and run attacker-controlled pull-request code.

GitHub Security Lab lists this Jupyter maintainer-tools advisory among vulnerabilities discovered with AI agents: a same-second race in update-snapshots-checkout could let an attacker make a privileged workflow check out and run attacker-controlled pull-request code.

Read the original story.

Source: Github