logo

Marimo Security Flaw Enables remote code execution Attacks

ID: 49320a2a-d213-58cd-b08e-cedb6eba18bb

STIX ID: report--49320a2a-d213-58cd-b08e-cedb6eba18bb

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Lucas Martin

...
...

A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo Python notebook framework lets unauthenticated attackers connect to /terminal/ws, trigger a PTY fork, and obtain an interactive system shell; the flaw is actively exploited in the wild to deliver NKAbuse malware via Hugging Face Spaces and affects all Marimo versions ≤ 0.22.x, with immediate upgrade to 0.23.0 and network/hardening mitigations recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.