hex livebook 0.19.9
v0.19.9
on Hex

4 hours ago

Fixed

  • Only proxy user-initiated events from JS widgets (CVE-2026-66298, GHSA-68c2-prqg-x62g)
  • Validate notebook file entry names on import to prevent path traversal reads and writes (CVE-2026-66881, GHSA-r4h8-2xpq-v48g)
  • Escape environment variables in app server shell instructions (CVE-2026-66297, GHSA-qpjc-w5mm-73mj)
  • App server Teams ZTA allowing access when its deployment group is removed (CVE-2026-68746, GHSA-74j5-6grg-g6wj)
  • Login CSRF in Teams identity callback (CVE-2026-66885, GHSA-pvvw-28fw-c6fg)

Don't miss a new livebook release

NewReleases is sending notifications on new releases.