Relative Path Traversal in Livebook by Livebook Dev
CVE-2026-66881
What is CVE-2026-66881?
Livebook contains a vulnerability that allows an attacker to create a file with malicious content at an arbitrary path due to a failure in validating file entry names. When an attacker supplies a crafted .livemd notebook containing URL-type file entries, the application incorrectly resolves and writes the specified file to the server's filesystem without proper containment checks. As a result, this vulnerability enables unauthorized file creation whenever the victim interacts with the attacker-controlled notebook, all under their authenticated session. This issue is present in Livebook versions from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9, highlighting a significant security risk for users of the application.
Affected Version(s)
livebook 0.11.0 < 0.18.7
livebook 0.19.0 < 0.19.9
livebook 0.11.0 < 0.18.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
