livebook
0.19.9
Automate code & data workflows with interactive notebooks
Current section
6 Advisories
Jump to
Current section
6 Advisories
Livebook Teams identity callback lacks state binding, allowing login CSRF
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66885.html
- https://github.com/livebook-dev/livebook/commit/21c16168263275541a6e076d0c31852c40e09a18
- https://github.com/livebook-dev/livebook/commit/33a052daa386c4ce08a9c39a07fc90f353ff6a51
- https://github.com/livebook-dev/livebook/commit/6ed2e213e9d5a19a70d7fcad5a8d616622cd2084
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-pvvw-28fw-c6fg
- https://hex.pm/packages/livebook
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66298.html
- https://github.com/livebook-dev/livebook/commit/296318ffdfa6e5ed7b18ad8d5a5b2af90f3cd728
- https://github.com/livebook-dev/livebook/commit/5980e5c6b71036806b3bf54101eb1d6c0f50f19c
- https://github.com/livebook-dev/livebook/commit/a552ce8f99ad348ea37061394dc950a0cebdb33e
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-68c2-prqg-x62g
- https://hex.pm/packages/livebook
Unescaped deployment environment variables in generated setup commands
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66297.html
- https://github.com/livebook-dev/livebook/commit/0c2487326bbb37cb1eb43bb2f76eb93ad9f8fd6b
- https://github.com/livebook-dev/livebook/commit/b2a8416d149043132fe5a14ed611e0fefc9dc9cd
- https://github.com/livebook-dev/livebook/commit/f8fe9c62cb8bfc1dd0ccda4ea4a57c5e91563c85
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-qpjc-w5mm-73mj
- https://hex.pm/packages/livebook
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-66881.html
- https://github.com/livebook-dev/livebook/commit/1443dd23df6e7b9203b6797f0695a807aeb81dde
- https://github.com/livebook-dev/livebook/commit/50f86982ebf36c22abeb379b55ec0f2859c83bb9
- https://github.com/livebook-dev/livebook/commit/acf4cb8c0c79b89c795b180f061be7de2d8b5aa9
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-r4h8-2xpq-v48g
- https://hex.pm/packages/livebook
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
Affected Versions
References
- https://cna.erlef.org/cves/CVE-2026-68746.html
- https://github.com/livebook-dev/livebook/commit/2d3a2c710c880abd24a2bc888d3cf5239d98cf72
- https://github.com/livebook-dev/livebook/commit/d374e90647edbb00286bfee9182c0161d29a8e07
- https://github.com/livebook-dev/livebook/commit/d6d0dfa746b172540442852f74de4a9deacc433b
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-74j5-6grg-g6wj
- https://hex.pm/packages/livebook
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows
Affected Versions
References
- https://github.com/livebook-dev/livebook
- https://github.com/livebook-dev/livebook/commit/2e11b59f677c6ed3b6aa82dad412a8b3406ffdf1
- https://github.com/livebook-dev/livebook/commit/beb10daaadcc765f0380e436bd7cd5f74cf086c8
- https://github.com/livebook-dev/livebook/releases/tag/v0.8.2
- https://github.com/livebook-dev/livebook/releases/tag/v0.9.3
- https://github.com/livebook-dev/livebook/security/advisories/GHSA-564w-97r7-c6p9
- https://nvd.nist.gov/vuln/detail/CVE-2023-35174
Checksum
Dependency Config
mix.exs
rebar.config
Gleam
erlang.mk
Package Details
this version
1 282
yesterday
73
last 7 days
1 924
all time
155 796