CVE-2026-66297 — Livebook Livebook: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability
Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command injection into generated deployment setup commands. LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.docker_instructions/2 and LivebookWeb.Hub.Teams.DeploymentGroupAgentComponent.fly_instructions/4 in lib/livebook_web/live/hub/teams/deployment_group_agent_component.ex interpolate deployment group environment variable values into th CVSSv3.1 8.0 (HIGH) · EPSS 68th percentile