Marimo RCE Vulnerability Exploited in the Within 10 Hours of Disclosure
ID: 89b17d43-a8bf-581d-bdf7-da4a27ee0271
STIX ID: report--89b17d43-a8bf-581d-bdf7-da4a27ee0271
Feed Name: cybersecurityNews.com
A critical pre-authentication RCE (CVE-2026-39987, CVSS 9.3) in Marimo's /terminal/ws WebSocket endpoint allowed unauthenticated attackers to spawn an interactive PTY shell; the flaw was exploited in the wild roughly 9 hours and 41 minutes after disclosure to locate and exfiltrate a .env file containing AWS access keys. The report provides the attacker source IP (49.207.56.74) and recommends immediate patching to Marimo 0.23.0+, restricting access to the endpoint, auditing environment variables, and rotating potentially compromised credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
