Marimo Security Flaw Enables remote code execution Attacks
ID: 49320a2a-d213-58cd-b08e-cedb6eba18bb
STIX ID: report--49320a2a-d213-58cd-b08e-cedb6eba18bb
Feed Name: Cyber Press
Threat Score
A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo Python notebook framework lets unauthenticated attackers connect to /terminal/ws, trigger a PTY fork, and obtain an interactive system shell; the flaw is actively exploited in the wild to deliver NKAbuse malware via Hugging Face Spaces and affects all Marimo versions ≤ 0.22.x, with immediate upgrade to 0.23.0 and network/hardening mitigations recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
