livebook is vulnerable to Path Traversal
70
High Risk
When importing a .livemd notebook, Livebook takes each file_entries name instead of applying the filename validation used by every user-interface path. For a URL-type entry, the name is resolved into the session's cache directory. A user who opens the notebook and causes the entry to be fetched writes the downloaded response body to a path outside the session sandbox. The fix validates file entry names on import to prevent traversal.
You are affected if you are using a version that falls within the vulnerable range and you open an untrusted notebook and evaluate or download a URL-type file entry it declares.
livebook is vulnerable to Path Traversal in versions 0.11.0 - 0.18.6 and 0.19.0 - 0.19.8.
Upgrade the livebook library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant