CVE-2026-66881: CWE-23 Relative Path Traversal in livebook-dev livebook
CVE-2026-66881 is a relative path traversal vulnerability in livebook-dev's livebook software. It allows an attacker to craft a malicious notebook that writes files with attacker-controlled content to arbitrary paths on the victim's system. This occurs because the import process does not properly validate file entry names, enabling path traversal outside the intended directory. The vulnerability affects livebook versions from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9. Exploitation requires a victim to open a malicious notebook and trigger the file fetch, with no authentication required for the attacker. The CVSS 4.0 score is 7.0, indicating high severity.
AI Analysis
Technical Summary
The vulnerability arises from insufficient validation of file entry names in .livemd notebooks imported into livebook. While the UI validates file entry names to be flat filenames, the import path takes the name verbatim, allowing path traversal sequences. When a URL-type file entry is fetched, the resolved path is not properly constrained within the session's temporary directory, allowing files to be written anywhere the livebook process has write permissions. This enables an attacker to write arbitrary files with attacker-controlled content on the victim's system by supplying a crafted notebook. The affected versions are livebook from 0.11.0 up to but not including 0.18.7, and from 0.19.0 up to but not including 0.19.9. There is no indication of an official patch or remediation level provided in the data. No known exploits in the wild have been reported.
Potential Impact
An attacker can cause arbitrary files to be written on the victim's system running livebook by supplying a malicious notebook. This can lead to unauthorized file creation or modification within any location writable by the livebook process. The attack requires the victim to open the malicious notebook and trigger the file fetch, potentially leading to local compromise or persistence. No privileges or authentication are required by the attacker to prepare the malicious notebook, but the victim must open it. The vulnerability has a high severity rating with a CVSS 4.0 score of 7.0.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid opening notebooks from untrusted sources. Monitoring for updates from the livebook-dev project is recommended to apply any forthcoming patches that address this path traversal issue.
CVE-2026-66881: CWE-23 Relative Path Traversal in livebook-dev livebook
Description
CVE-2026-66881 is a relative path traversal vulnerability in livebook-dev's livebook software. It allows an attacker to craft a malicious notebook that writes files with attacker-controlled content to arbitrary paths on the victim's system. This occurs because the import process does not properly validate file entry names, enabling path traversal outside the intended directory. The vulnerability affects livebook versions from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9. Exploitation requires a victim to open a malicious notebook and trigger the file fetch, with no authentication required for the attacker. The CVSS 4.0 score is 7.0, indicating high severity.
CVSS v4.0
Score 7.0high
Affected software
livebook-dev
livebook
livebook-dev
livebook
livebook-dev
livebook
cpe:2.3:a:livebook-dev:livebook:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from insufficient validation of file entry names in .livemd notebooks imported into livebook. While the UI validates file entry names to be flat filenames, the import path takes the name verbatim, allowing path traversal sequences. When a URL-type file entry is fetched, the resolved path is not properly constrained within the session's temporary directory, allowing files to be written anywhere the livebook process has write permissions. This enables an attacker to write arbitrary files with attacker-controlled content on the victim's system by supplying a crafted notebook. The affected versions are livebook from 0.11.0 up to but not including 0.18.7, and from 0.19.0 up to but not including 0.19.9. There is no indication of an official patch or remediation level provided in the data. No known exploits in the wild have been reported.
Potential Impact
An attacker can cause arbitrary files to be written on the victim's system running livebook by supplying a malicious notebook. This can lead to unauthorized file creation or modification within any location writable by the livebook process. The attack requires the victim to open the malicious notebook and trigger the file fetch, potentially leading to local compromise or persistence. No privileges or authentication are required by the attacker to prepare the malicious notebook, but the victim must open it. The vulnerability has a high severity rating with a CVSS 4.0 score of 7.0.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid opening notebooks from untrusted sources. Monitoring for updates from the livebook-dev project is recommended to apply any forthcoming patches that address this path traversal issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EEF
- Date Reserved
- 2026-07-28T04:15:10.239Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a739c88bf8831d5396b301e
Added to database: 08/05/2026, 20:26:48 UTC
Last enriched: 08/13/2026, 17:34:47 UTC
Last updated: 09/18/2026, 00:31:33 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.