livebook-dev vulnerabilities
5 CVEs tracked
Livebook-dev appears in our recent reporting with a cluster of critical vulnerabilities centered on identity management and untrusted notebook execution. The main themes involve a failing-open authentication mechanism (CVE-2026-68746), a dangerous Cross-Site Request Forgery attack (CVE-2026-66885), and command injection potentially leading to full server compromise (CVE-2026-66297). Defenders should prioritize the OS Command Injection via CVE-2026-66297, the origin validation error via CVE-2026-66298, the Relative Path Traversal via CVE-2026-66881, the CSRF authentication hijack via CVE-2026-66885, and the failing-open authentication via CVE-2026-68746; immediate patching and a review of Livebook Teams configurations are required.
Azərbaycanca: Livebook-dev son hesabatlarımızda identiklik idarəetməsi və qeyri-mötəbər notebook icrası ilə bağlı kritik boşluqlarla diqqət çəkir. Əsas hadisələr səriştəsiz autentifikasiya mexanizmi (CVE-2026-68746), təhlükəli Cross-Site Request Forgery hücumu (CVE-2026-66885) və potensial olaraq serverin tam ələ keçirilməsinə səbəb ola biləcək əmr inyeksiyası (CVE-2026-66297) ətrafında cəmlənir. Müdafiəçilər bu vendor üçün ilk növbədə CVE-2026-66297 vasitəsilə OS Command Injection, CVE-2026-66298 vasitəsilə mənşə doğrulama səhvi, CVE-2026-66881 vasitəsilə Relative Path Traversal, CVE-2026-66885 vasitəsilə CSRF autentifikasiya oğurluğu, CVE-2026-68746 vasitəsilə isə autentifikasiyanın 'failing open' olması zəifliklərinə diqqət yetirməli, dərhal təhlükəsizlik yamalarını tətbiq etməli və xüsusilə Livebook Teams konfiqurasiyasını nəzərdən keçirməlidir.
This vendor's CVEs5
This hub is built from skopnix's own reporting on livebook-dev: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.