Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:hex/livebook

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-66885 is a Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook when configured with Livebook Teams for identity. An attacker in the same Livebook Teams organization can cause a victim's browser session to authenticate as the attacker by tricking the victim into using a crafted URL with an authorization code. This results in the victim unknowingly operating under the attacker's identity, exposing any work or secrets to the attacker. The vulnerability affects livebook versions from 0.15.0 before 0.18.7 and from 0.19.0 before 0.19.9. The CVSS 4.0 score is 6.8 (medium severity).

Join the discussion

CVE-2026-66298 is an origin validation error vulnerability in livebook-dev's livebook software that allows untrusted JavaScript in notebook outputs to trigger session-wide keyboard shortcuts. This can cause forced evaluation of all notebook cells and runtime restarts without user consent. The vulnerability arises because the trusted iframe forwards all keydown events to the parent page without verifying their authenticity, enabling malicious scripts to simulate genuine keystrokes. Affected versions include 0.5.0 before 0.18.7 and 0.19.0 before 0.19.9.

Join the discussion

CVE-2026-66297 is an OS Command Injection vulnerability in livebook-dev livebook that allows command injection into generated deployment setup commands. The vulnerability arises because deployment group environment variable values are interpolated into Docker and Fly.io setup commands without proper shell escaping. This can lead to execution of arbitrary commands on the machine of the user who runs the generated command. An attacker must have privileges to set deployment group environment variables to exploit this issue. Kubernetes instructions are not affected due to proper escaping in YAML manifests. The vulnerability affects livebook versions from 0.13.0 before 0.18.7 and from 0.19.0 before 0.19.9.

Join the discussion

CVE-2026-66881 is a relative path traversal vulnerability in livebook-dev's livebook software. It allows an attacker to craft a malicious notebook that writes files with attacker-controlled content to arbitrary paths on the victim's system. This occurs because the import process does not properly validate file entry names, enabling path traversal outside the intended directory. The vulnerability affects livebook versions from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9. Exploitation requires a victim to open a malicious notebook and trigger the file fetch, with no authentication required for the attacker. The CVSS 4.0 score is 7.0, indicating high severity.

Join the discussion

CVE-2026-68746 is a high-severity vulnerability in livebook-dev livebook versions 0.19.7 through before 0.19.9. It allows an unauthenticated network client to gain full access to a Livebook server that uses Livebook Teams for identity enforcement. The issue arises when a deployment group is deleted while the agent is disconnected, causing the client to cache an unresolved identifier and incorrectly grant full access. This includes reading notebooks, secrets, executing code, and disrupting server operations.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:hex/livebook
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses