VDB
Sign up
HIGH8.6

GHSA-564w-97r7-c6p9

Livebook Desktop's protocol handler can be exploited to execute arbitrary command on Windows

Quick fix

GHSA-564w-97r7-c6p9 — livebook: upgrade to the fixed version with the command below.

mix deps.update livebook

Details

On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine.

Any user using Livebook Desktop on Windows is potentially vulnerable to arbitrary code execution when they expect Livebook to be opened from browser.

Are you affected?

Enter the version of the package you're using.

Affected packages

Hex/livebook
Introduced in: 0.8.0Fixed in: 0.8.2
Fixmix deps.update livebook
Hex/livebook
Introduced in: 0.9.0Fixed in: 0.9.3
Fixmix deps.update livebook

References