VYPR
High severity8.6NVD Advisory· Published Jun 22, 2023· Updated Jun 17, 2026

CVE-2023-35174

CVE-2023-35174

Description

Livebook is a web application for writing interactive and collaborative code notebooks. On Windows, it is possible to open a livebook:// link from a browser which opens Livebook Desktop and triggers arbitrary code execution on victim's machine. Any user using Livebook Desktop on Windows is potentially vulnerable to arbitrary code execution when they expect Livebook to be opened from browser. This vulnerability has been fixed in version 0.8.2 and 0.9.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
livebookHex
>= 0.8.0, < 0.8.20.8.2
livebookHex
>= 0.9.0, < 0.9.30.9.3

Affected products

3

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.