Relative Path Traversal in Livebook by Livebook Dev
CVE-2026-66881

7HIGH

Key Information:

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-66881?

Livebook contains a vulnerability that allows an attacker to create a file with malicious content at an arbitrary path due to a failure in validating file entry names. When an attacker supplies a crafted .livemd notebook containing URL-type file entries, the application incorrectly resolves and writes the specified file to the server's filesystem without proper containment checks. As a result, this vulnerability enables unauthorized file creation whenever the victim interacts with the attacker-controlled notebook, all under their authenticated session. This issue is present in Livebook versions from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9, highlighting a significant security risk for users of the application.

Affected Version(s)

livebook 0.11.0 < 0.18.7

livebook 0.19.0 < 0.19.9

livebook 0.11.0 < 0.18.7

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyá»…n CĂ´ng TĂş
Jonatan Männchen / EEF
Jonatan Kłosko
José Valim
.