All 6 CVE vulnerabilities found in livebook, with AI-generated Chinese analysis, references, and POCs.
Vendor: livebook-dev
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-66885 | Livebook Teams identity callback lacks state binding, allowing login CSRF CWE-352 | 6.8 | Medium | 2026-08-05 |
| CVE-2026-66298 | JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts CWE-346 | 8.6 | High | 2026-08-05 |
| CVE-2026-66297 | Unescaped deployment environment variables in generated setup commands CWE-78 | 5.0 | Medium | 2026-08-05 |
| CVE-2026-66881 | Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download CWE-23 | 7.0 | High | 2026-08-05 |
| CVE-2026-68746 | Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access CWE-636 | 7.7 | High | 2026-08-05 |
| CVE-2023-35174 | Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows CWE-78 | 8.6 | High | 2023-06-22 |
All 6 known CVE vulnerabilities affecting livebook with full Chinese analysis, references, and POCs where available.