Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure
ID: ee1b3085-fe27-525b-99b3-85fa403c0828
STIX ID: report--ee1b3085-fe27-525b-99b3-85fa403c0828
Feed Name: Cyber Press
A critical unauthenticated RCE (CVE-2026-39987, CVSS 9.3) in Marimo's /terminal/ws WebSocket endpoint was weaponized and exploited in the wild within about 9 hours and 41 minutes of disclosure, allowing attackers to spawn interactive shells, read configuration and environment files (including AWS credentials), and perform manual follow-up activity; Sysdig telemetry observed rapid automation and manual intrusions, and users are advised to upgrade to Marimo 0.23.0 and rotate exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
