← Back

CVE-2023-35174

nvd nist
Published: Jun 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a `livebook://` link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any user using Livebook Desktop on Windows is potentially vulnerable to arbitrary code execution when they expect Livebook to be opened from browser. This vulnerability has been fixed in version 0.8.2 and 0.9.3.

Affected (2)

Products: Livebook: Livebook
1 product
Livebook
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Livebook
From 0.8.0 to 0.8.2
From 0.9.0 to 0.9.3
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (10)

Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.