Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely
ID: ab9da2ce-7201-521b-a5e2-74bb36c79e1f
STIX ID: report--ab9da2ce-7201-521b-a5e2-74bb36c79e1f
Feed Name: GBHackers
**Critical unauthenticated RCE in Marimo (CVE-2026-39987):** A pre-authentication flaw in the /terminal/ws WebSocket endpoint allows remote attackers to obtain an interactive PTY shell (spawned via pty.fork()), enabling full system compromise; active exploitation has been reported with NKAbuse malware delivery, and affected Marimo versions are those prior to 0.23.0 — remediation is to upgrade to 0.23.0+, restrict network exposure (VPN/private subnets/reverse proxies), enforce non-root execution, rotate credentials, and monitor suspicious WebSocket/terminal activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
