Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
ID: eefd38a7-9125-58ce-9b37-2037acd461bc
STIX ID: report--eefd38a7-9125-58ce-9b37-2037acd461bc
Feed Name: ThreatCluster
Threat Score
A critical pre-authentication remote code execution (CVE-2026-39987) in the Marimo Python notebook platform was disclosed on 2026-04-08 and exploited within 9 hours 41 minutes; attackers used unauthenticated access to the /terminal/ws WebSocket endpoint to gain full control and exfiltrate AWS credentials in under three minutes. The flaw affects all versions prior to 0.23.0 (CVSS 9.3) and Marimo users are advised to upgrade to version 0.23.0 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
