🔐 CVE Alert

CVE-2026-66881

UNKNOWN 0.0

Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a file entry through the user interface validates that name with Livebook.Notebook.validate_file_entry_name/2, which requires a flat filename of alphanumerics, dashes, underscores and dots, ending in an extension. The import path does not: Livebook.LiveMarkdown.Import.file_entry_metadata_to_attrs/1 in lib/livebook/live_markdown/import.ex takes the name verbatim from the notebook source. For a URL-type file entry, Livebook.Session.file_entry_cache_file/2 in lib/livebook/session.ex resolves that name beneath the session's temporary directory without checking that the result stays inside it, and Livebook.FileSystem.Utils.resolve_unix_like_path/2 collapses parent-directory segments while clamping only at the filesystem root. When the entry's content is requested and no cached copy exists, Livebook fetches the entry's URL and writes the response body to the resolved path, creating parent directories as needed. The attacker therefore controls both the destination and the contents of the written file, which may land anywhere the Livebook process can write. The same missing containment check is present in Livebook.Session.to_attachment_file_entry/2. A victim who opens an attacker-supplied notebook and causes the entry to be fetched triggers the write within their own authenticated session; the attacker needs no account on the target instance. URL-type entries are also not placed under notebook stamping quarantine on import, so no warning is shown. This issue affects livebook: from 0.11.0 before 0.18.7 and from 0.19.0 before 0.19.9.

CWE CWE-23
Vendor livebook-dev
Product livebook
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for livebook-dev livebook

Be the first to know when new unknown vulnerabilities affecting livebook-dev livebook are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

livebook-dev / livebook
0.11.0 < 0.18.7 0.19.0 < 0.19.9
livebook-dev / livebook
0.11.0 < 0.18.7 0.19.0 < 0.19.9 0.11.0-cuda12 < 0.18.7-cuda12 0.19.0-cuda12 < 0.19.9-cuda12
livebook-dev / livebook
c02eb984f80a543c7a52b1d882c76f56aa5be743 < *

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/livebook-dev/livebook/security/advisories/GHSA-r4h8-2xpq-v48g cna.erlef.org: https://cna.erlef.org/cves/CVE-2026-66881.html osv.dev: https://osv.dev/vulnerability/EEF-CVE-2026-66881 github.com: https://github.com/livebook-dev/livebook/commit/1443dd23df6e7b9203b6797f0695a807aeb81dde github.com: https://github.com/livebook-dev/livebook/commit/acf4cb8c0c79b89c795b180f061be7de2d8b5aa9 github.com: https://github.com/livebook-dev/livebook/commit/50f86982ebf36c22abeb379b55ec0f2859c83bb9

Credits

Nguyễn Công Tú Jonatan Männchen / EEF Jonatan Kłosko José Valim