Cross-Site Request Forgery Vulnerability in Livebook by Livebook Dev
CVE-2026-66885

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-66885?

A Cross-Site Request Forgery (CSRF) vulnerability in Livebook allows an attacker, who is a member of the same Livebook Teams organization, to manipulate the authentication process. By leveraging a crafted URL that contains an authorization code, the attacker can trick a victim into initiating a login flow. This causes the victim's session to be hijacked, resulting in the user unknowingly operating under the attacker's identity. Any actions taken or data uploaded during this session are attributed to the attacker, exposing sensitive information and compromising user privacy. This vulnerability primarily arises from a lack of state verification in the OAuth callback process.

Affected Version(s)

livebook 0.15.0 < 0.18.7

livebook 0.19.0 < 0.19.9

livebook 0.15.0 < 0.18.7

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyá»…n CĂ´ng TĂş
Jonatan Kłosko
José Valim
Hugo BaraĂşna
.