Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure
ID: 62b8bbf6-2565-53ad-9758-58e73a62e7b0
STIX ID: report--62b8bbf6-2565-53ad-9758-58e73a62e7b0
Feed Name: GBHackers
Threat Score
A critical RCE (CVE-2026-39987) in Marimo's terminal WebSocket endpoint (/terminal/ws) allowed unauthenticated attackers to gain a full interactive shell; researchers observed exploitation in the wild roughly 9 hours after disclosure, with attackers quickly locating and exfiltrating a .env file containing active AWS credentials. Administrators are urged to upgrade Marimo to 0.23.0, review terminal-path connections, and rotate any exposed keys or secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
