Skip to finding
important · CI privilege

A timing race in JupyterLab's snapshot action can execute pull-request contributor code in a privileged CI job.

Affects

JupyterLab maintainer-tools, reusable GitHub Actions workflows used by software repositories to update pull-request snapshots.

After a maintainer approves a snapshot update, a contributor can push a malicious revision within the same one-second timestamp interval. The action treats it as unchanged and checks it out as the approved revision.

Detail and 2 sources

The checked-out code inherits the consuming job's secrets and authority. GitHub Security Lab tested the sequence against jupyter/notebook.

A patched action release exists, but consuming workflows can continue referencing the vulnerable release.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026