AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T20:17:14.393Z and has not been modified since then. This vulnerability affects livebook-dev livebook, allowing an unauthenticated network client to obtain full access to a Livebook server that enforces identity through Livebook Teams when the identity status is reported as switched off due to a d [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T20:17:13.007Z and has not been modified since then. The CVE-2026-66885 issue arises from a Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook. When Livebook is configured to use Livebook Teams for identity, an attacker can authenticate a victim's browser session under the at [truncated]
The CVE-2026-66881 vulnerability in livebook-dev livebook is a Relative Path Traversal issue that allows an attacker-authored notebook to write files with attacker-controlled content to arbitrary paths. This arises from insufficient containment checks when resolving file entry names for URL-type entries in .livemd notebooks. The vulnerability affects livebook versions from 0.11.0 before 0.18.7 and from 0. [truncated]
The livebook application has an Improper Neutralization of Special Elements used in an OS Command vulnerability, allowing command injection into generated deployment setup commands. This affects livebook versions from 0.13.0 before 0.18.7 and from 0.19.0 before 0.19.9. The vulnerability is caused by LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and LivebookWeb.Hub.Teams.Deploym [truncated]