livebook is vulnerable to Origin Validation Error
86
High Risk
Livebook renders notebook-defined JavaScript inside a sandboxed cross-origin iframe, but the iframe shell forwards every keydown event to the parent page without checking Event.isTrusted. Untrusted output scripts can synthesize keyboard events and drive Livebook's global shortcuts, forcing full notebook evaluation, restarting the runtime, or deleting cells in the browser of anyone viewing the output. The fix only proxies genuine user-initiated events from JS widgets.
You are affected if you are using a version that falls within the vulnerable range and you open or view untrusted notebooks that render JavaScript outputs.
livebook is vulnerable to Origin Validation Error in versions 0.5.0 - 0.18.6 and 0.19.0 - 0.19.8.
Upgrade the livebook library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant