Livebook · Livebook · CVE-2023-35174
**Name of the Vulnerable Software and Affected Versions**
Livebook versions prior to 0.8.2
Livebook versions prior to 0.9.3
**Description**
The issue allows arbitrary code execution on a victim's machine when a `livebook://` link is opened from a browser, triggering Livebook Desktop to execute the code. This can happen when a user expects Livebook to be opened from a browser.
**Recommendations**
For versions prior to 0.8.2, update to version 0.8.2 or later.
For versions prior to 0.9.3, update to version 0.9.3 or later.
As a temporary workaround, consider avoiding the use of `livebook://` links from browsers until the issue is resolved.