—Hex
EEF-CVE-2026-66297· CVE-2026-66297, GHSA-qpjc-w5mm-73mjUnescaped deployment environment variables in generated setup commands
Modified: 9/8/2026
package
pkg:hex/livebook
Unescaped deployment environment variables in generated setup commands
Modified: 9/8/2026
JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts
Modified: 9/8/2026
Path traversal in imported file_entries name allows arbitrary file write via URL-type entry download
Modified: 9/8/2026
Livebook Teams identity callback lacks state binding, allowing login CSRF
Modified: 9/8/2026
Livebook Teams identity check fails open when the deployment group is unresolvable, allowing unauthenticated access
Modified: 9/8/2026
Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows
Modified: 12/10/2025