logo

Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure

ID: 62b8bbf6-2565-53ad-9758-58e73a62e7b0

STIX ID: report--62b8bbf6-2565-53ad-9758-58e73a62e7b0

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Divya

...
...

A critical RCE (CVE-2026-39987) in Marimo's terminal WebSocket endpoint (/terminal/ws) allowed unauthenticated attackers to gain a full interactive shell; researchers observed exploitation in the wild roughly 9 hours after disclosure, with attackers quickly locating and exfiltrating a .env file containing active AWS credentials. Administrators are urged to upgrade Marimo to 0.23.0, review terminal-path connections, and rotate any exposed keys or secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.