CVE-2026-66881 | livebook-dev livebook up to 0.18.6/0.19.8 Import import.ex Name path traversal

SecurityVulns

A vulnerability identified as problematic has been detected in livebook-dev livebook up to 0.18.6/0.19.8. This impacts the function Livebook.LiveMarkdown.Import.file_entry_metadata_to_attrs of the file lib/livebook/live_markdown/import.ex of the component Import. This manipulation of the argument Name causes path traversal.

This vulnerability is registered as CVE-2026-66881. Remote exploitation of the attack is possible. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More