logo

Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours

ID: 5d9b2e17-eec2-5a51-b422-8781d4623bc4

STIX ID: report--5d9b2e17-eec2-5a51-b422-8781d4623bc4

Feed Name: Sysdig Blog

Threat Score
80/100

Date Published: 2026-04-09

Date Updated: 2026-05-01

...
...

**Executive summary:** A critical pre-auth RCE in marimo's /terminal/ws WebSocket endpoint (GHSA-2679-6mx9-h9xc, CVSS 9.3) was disclosed and weaponized within 9 hours 41 minutes; Sysdig TRT honeypots recorded an attacker (49.207.56.74) obtaining an interactive shell and exfiltrating .env credentials in under three minutes, demonstrating rapid exploitation of niche-project advisories and high risk of cloud credential compromise—patch to marimo 0.23.0, restrict/disable the terminal endpoint, rotate exposed secrets, and monitor WebSocket traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.