logo

Critical RCE Vulnerability in Marimo Exploited Within Hours of Disclosure

ID: 8f36d4cf-0f9b-53c0-ac53-9ec7688a9d7f

STIX ID: report--8f36d4cf-0f9b-53c0-ac53-9ec7688a9d7f

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-12

Date Updated: 2026-04-12

...
...

A critical pre-authentication remote code execution vulnerability (CVE-2026-39987) in the Marimo open-source Python notebook platform was disclosed on April 8, 2026 and was observed being exploited in the wild within about 9 hours and 41 minutes, enabling attackers to obtain interactive shells via the /terminal/ws WebSocket endpoint and perform rapid credential theft; Marimo users (<=0.20.4) are urged to upgrade to version 0.23.0 immediately to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.