Browse all 6 CVE security advisories affecting livebook-dev. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-66885 | Livebook Teams identity callback lacks state binding, allowing login CSRF — livebook CWE-352 | 6.8 | Medium | 2026-08-05 |
| CVE-2026-66298 | JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts — livebook CWE-346 | 8.6 | High | 2026-08-05 |
| CVE-2026-66297 | Unescaped deployment environment variables in generated setup commands — livebook CWE-78 | 5.0 | Medium | 2026-08-05 |
| CVE-2026-66881 | Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download — livebook CWE-23 | 7.0 | High | 2026-08-05 |
| CVE-2026-68746 | Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access — livebook CWE-636 | 7.7 | High | 2026-08-05 |
| CVE-2023-35174 | Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows — livebook CWE-78 | 8.6 | High | 2023-06-22 |
This page lists every published CVE security advisory associated with livebook-dev. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.