livebook
Hex6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting livebookpage 1 of 1
- CVE-2023-35174HIGHCVSS 8.6EG 8.6✓ Fixed in 0.9.32023-06-22
vulnerable: 0.9.0, 0.9.1, 0.9.2
Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's m…
- CVE-2026-66297HIGHCVSS 8.0EG 8.0✓ Fixed in 0.19.92026-08-05
vulnerable: 0.13.0 ... 0.19.8 (45 versions)
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentC…
- CVE-2026-66298HIGHCVSS 8.8EG 8.8✓ Fixed in 0.19.92026-08-05
vulnerable: 0.10.0 ... 0.9.3 (70 versions)
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view featur…
- CVE-2026-66881HIGHCVSS 8.1EG 8.1✓ Fixed in 0.19.92026-08-05
vulnerable: 0.11.0 ... 0.19.8 (52 versions)
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry ca…
- CVE-2026-66885MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.19.92026-08-05
vulnerable: 0.15.0 ... 0.19.8 (31 versions)
Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. When Livebook is configured to use Livebook Teams for…
- CVE-2026-68746HIGHCVSS 8.8EG 8.8✓ Fixed in 0.19.92026-08-05
vulnerable: 0.19.7, 0.19.8
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams. A Livebook Agent or App Server…
Check whether livebook is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for livebook CVEs against the assets you own.
Start Free Scan →