Cross-Site Request Forgery Vulnerability in Livebook by Livebook Dev
CVE-2026-66885
What is CVE-2026-66885?
A Cross-Site Request Forgery (CSRF) vulnerability in Livebook allows an attacker, who is a member of the same Livebook Teams organization, to manipulate the authentication process. By leveraging a crafted URL that contains an authorization code, the attacker can trick a victim into initiating a login flow. This causes the victim's session to be hijacked, resulting in the user unknowingly operating under the attacker's identity. Any actions taken or data uploaded during this session are attributed to the attacker, exposing sensitive information and compromising user privacy. This vulnerability primarily arises from a lack of state verification in the OAuth callback process.
Affected Version(s)
livebook 0.15.0 < 0.18.7
livebook 0.19.0 < 0.19.9
livebook 0.15.0 < 0.18.7
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
