logo

Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure

ID: ee1b3085-fe27-525b-99b3-85fa403c0828

STIX ID: report--ee1b3085-fe27-525b-99b3-85fa403c0828

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-04-13

Date Updated: 2026-04-13

Author: AnuPriya

...
...

A critical unauthenticated RCE (CVE-2026-39987, CVSS 9.3) in Marimo's /terminal/ws WebSocket endpoint was weaponized and exploited in the wild within about 9 hours and 41 minutes of disclosure, allowing attackers to spawn interactive shells, read configuration and environment files (including AWS credentials), and perform manual follow-up activity; Sysdig telemetry observed rapid automation and manual intrusions, and users are advised to upgrade to Marimo 0.23.0 and rotate exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.