Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-66298

PUBLISHED 05.08.2026

CNA: EEF

JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts

Обновлено: 05.08.2026
Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts, including forced evaluation of all cells and runtime restart. Livebook's JS-view feature renders notebook-defined JavaScript inside a sandboxed, cross-origin iframe specifically because that JavaScript is untrusted. The trusted iframe shell in iframe/priv/static/iframe/v5.html forwards every keydown event fired in its own window to the parent page without consulting Event.isTrusted, so an event synthesized by the untrusted script through window.dispatchEvent is forwarded exactly as a genuine keystroke would be. The parent-side relay in assets/js/hooks/js_view.js reconstructs and re-dispatches it on the live page with no further validation, and because assets/js/hooks/session.js registers the global shortcut handler on the document in the capture phase, that handler acts on the replicated event regardless of how it was produced. Sandboxed output JavaScript can therefore drive Livebook's session-wide keyboard shortcuts. Two of them reach LivebookWeb.SessionLive and execute immediately with no confirmation: the shortcut for queueing full evaluation runs every cell in the notebook, and the shortcut for reconnecting the runtime disconnects and reconnects it, discarding in-memory state. A third shortcut deletes the focused cell behind a confirmation dialog that the user can permanently dismiss, after which it too executes silently. Forced full evaluation is the significant consequence, because it causes the notebook's own Elixir code to run without the user choosing to evaluate anything. A user who merely opens a notebook obtained from a third party, or reached from published documentation, can have its code executed on their runtime. Livebook also mirrors cell outputs to every connected client, so a malicious output triggers in a collaborator's browser as soon as it renders. This issue affects livebook: from 0.5.0 before 0.18.7 and from 0.19.0 before 0.19.9.

CWE

Идентификатор Описание
CWE-346 The product does not properly verify that the source of data or communication is valid.

CVSS

Оценка Severity Версия Базовый вектор
8.6 HIGH 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Доп. Информация

Product Status

livebook
Product: livebook
Vendor: livebook-dev
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0.5.0 до 0.18.7 affected
Наблюдалось в версиях от 0.19.0 до 0.19.9 affected
СPE:
  • cpe:2.3:a:livebook-dev:livebook:*:*:*:*:*:*:*:*
livebook
Product: livebook
Vendor: livebook-dev
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0.5.0 до 0.18.7 affected
Наблюдалось в версиях от 0.19.0 до 0.19.9 affected
Наблюдалось в версиях от 0.5.0-cuda12 до 0.18.7-cuda12 affected
Наблюдалось в версиях от 0.19.0-cuda12 до 0.19.9-cuda12 affected
СPE:
  • cpe:2.3:a:livebook-dev:livebook:*:*:*:*:*:*:*:*
livebook
Product: livebook
Vendor: livebook-dev
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 844242ba80a928d0d675416d312a58003cb7771b до * affected
СPE:
  • cpe:2.3:a:livebook-dev:livebook:*:*:*:*:*:*:*:*
 

Ссылки

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.