livebook is vulnerable to Cross-Site Request Forgery (CSRF)
68
Medium Risk
The Livebook Teams identity callback exchanges an authorization code for a token and writes it into the browser session without any state or nonce binding to the session that started the login. A member of the same Livebook Teams organization can begin a login flow, retain the code, and induce another user to open a URL carrying it, completing authentication under the initiator's identity. The victim then works in a session attributed to another account, exposing secrets, uploads, and notebook results. The fix binds the callback to the initiating session with state validation.
You are affected if you are using a version that falls within the vulnerable range and your instance uses Livebook Teams identity for authentication.
livebook is vulnerable to Cross-Site Request Forgery (CSRF) in versions 0.15.0 - 0.18.6 and 0.19.0 - 0.19.8.
Upgrade the livebook library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant