Skip to content

v0.19.9

Latest

Choose a tag to compare

@livebook-bot livebook-bot released this 05 Aug 15:55

Fixed

  • Only proxy user-initiated events from JS widgets (CVE-2026-66298, GHSA-68c2-prqg-x62g)
  • Validate notebook file entry names on import to prevent path traversal reads and writes (CVE-2026-66881, GHSA-r4h8-2xpq-v48g)
  • Escape environment variables in app server shell instructions (CVE-2026-66297, GHSA-qpjc-w5mm-73mj)
  • App server Teams ZTA allowing access when its deployment group is removed (CVE-2026-68746, GHSA-74j5-6grg-g6wj)
  • Login CSRF in Teams identity callback (CVE-2026-66885, GHSA-pvvw-28fw-c6fg)