What is CVE-2026-66885?
CVE-2026-66885 is a Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev's Livebook application. When Livebook is configured with Livebook Teams for identity, the flaw allows an attacker to authenticate a victim's browser session under the attacker's own Livebook Teams identity. Users are advised to update Livebook to the latest patched version.
Azərbaycanca: CVE-2026-66885, livebook-dev tərəfindən hazırlanmış Livebook proqramında aşkarlanmış Cross-Site Request Forgery (CSRF) zəifliyidir. Bu zəiflik, Livebook Teams identifikasiyası aktiv olduqda, təcavüzkara qurbanın brauzer sessiyasını öz Livebook Teams şəxsiyyəti altında autentifikasiya etməyə imkan verir. İstifadəçilərə Livebook-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Under what conditions can CVE-2026-66885 be exploited?
This vulnerability can only be exploited when the Livebook application is configured with Livebook Teams for identity.
What can an attacker achieve by exploiting CVE-2026-66885?
The attacker can authenticate a victim's browser session under the attacker's own Livebook Teams identity.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.