logo

Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure

ID: eefd38a7-9125-58ce-9b37-2037acd461bc

STIX ID: report--eefd38a7-9125-58ce-9b37-2037acd461bc

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-12

Date Updated: 2026-04-13

...
...

A critical pre-authentication remote code execution (CVE-2026-39987) in the Marimo Python notebook platform was disclosed on 2026-04-08 and exploited within 9 hours 41 minutes; attackers used unauthenticated access to the /terminal/ws WebSocket endpoint to gain full control and exfiltrate AWS credentials in under three minutes. The flaw affects all versions prior to 0.23.0 (CVSS 9.3) and Marimo users are advised to upgrade to version 0.23.0 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.