What is CVE-2026-66298?
This Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook JavaScript output to escape its sandbox and trigger system-wide keyboard shortcuts, leading to forced cell evaluation or runtime restart. Users should immediately apply the vendor-issued security patch and avoid loading untrusted notebooks.
Azərbaycanca: Bu zəiflik livebook-dev livebook platformasında notebook-un etibarsız JavaScript çıxışının sandbox mühitini keçərək istifadəçinin klaviatura qısayollarını ələ keçirməsinə, bütün xanaların məcburi icrasına və ya runtime mühitinin yenidən başladılmasına səbəb ola bilər. İstifadəçilər dərhal tərtibatçı tərəfindən təqdim ediləcək təhlükəsizlik yeniləməsini tətbiq etməli və etibarsız notebook-ları yükləməkdən çəkinməlidir.
Related CVEs
link basis: shared vendor: livebook-dev
FAQ2
What type of security vulnerability is CVE-2026-66298 in the livebook platform?
It is an Origin Validation Error vulnerability. Untrusted notebook JavaScript output can escape its sandbox.
What measures should livebook users take to protect against CVE-2026-66298?
Users should immediately apply the vendor-issued security patch and avoid loading untrusted notebooks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.