Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit
ID: 8c92cbde-c172-5e68-92dd-fc5dc8a2dcf2
STIX ID: report--8c92cbde-c172-5e68-92dd-fc5dc8a2dcf2
Feed Name: Sysdig Blog
Sysdig Threat Research observed active exploitation of CVE-2026-39987 in marimo notebook instances: an unauthenticated /terminal/ws WebSocket led to pre-auth RCE, credential harvesting from environment/Redis, Secrets Manager calls to retrieve an SSH key, and an eight-second credential-to-bastion SSH pivot using hand-rolled Python tooling. The report provides a detailed timeline, reproduced attacker scripts, IOCs (source and C2 IPs, /tmp filenames, command patterns), detection guidance (focus on chain-shaped behavior and CloudTrail patterns), and mitigations including updating marimo, restricting the terminal endpoint, scoping Secrets Manager access, and egress restrictions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
