CVE-2026-66885
- EPSS 0.16%
- Veröffentlicht 05.08.2026 19:44:23
- Zuletzt bearbeitet 10.08.2026 16:52:00
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for identity, ...
CVE-2026-66298
- EPSS 0.17%
- Veröffentlicht 05.08.2026 19:44:11
- Zuletzt bearbeitet 10.08.2026 18:10:29
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders n...
- EPSS 1.55%
- Veröffentlicht 05.08.2026 19:43:58
- Zuletzt bearbeitet 10.08.2026 15:17:10
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.do...
CVE-2026-66881
- EPSS 0.38%
- Veröffentlicht 05.08.2026 19:43:48
- Zuletzt bearbeitet 10.08.2026 18:00:45
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a na...
CVE-2026-68746
- EPSS 0.45%
- Veröffentlicht 05.08.2026 19:43:38
- Zuletzt bearbeitet 10.08.2026 16:47:23
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server connected ...
CVE-2023-35174
- EPSS 0.98%
- Veröffentlicht 22.06.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:05
Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any...