Critical RCE Vulnerability in Marimo Exploited Within Hours of Disclosure
ID: 8f36d4cf-0f9b-53c0-ac53-9ec7688a9d7f
STIX ID: report--8f36d4cf-0f9b-53c0-ac53-9ec7688a9d7f
Feed Name: ThreatCluster
Threat Score
A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo open-source Python notebook platform was disclosed on April 8, 2026 and was observed being exploited in the wild within about 9 hours and 41 minutes, enabling attackers to obtain interactive shells via the /terminal/ws WebSocket endpoint and perform rapid credential theft; Marimo users (<=0.20.4) are urged to upgrade to version 0.23.0 immediately to mitigate risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
