logo

Critical Marimo RCE Flaw Could Let Attackers Execute Malicious Code Remotely

ID: ab9da2ce-7201-521b-a5e2-74bb36c79e1f

STIX ID: report--ab9da2ce-7201-521b-a5e2-74bb36c79e1f

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Divya

...
...

**Critical unauthenticated RCE in Marimo (CVE-2026-39987):** A pre-authentication flaw in the /terminal/ws WebSocket endpoint allows remote attackers to obtain an interactive PTY shell (spawned via pty.fork()), enabling full system compromise; active exploitation has been reported with NKAbuse malware delivery, and affected Marimo versions are those prior to 0.23.0 — remediation is to upgrade to 0.23.0+, restrict network exposure (VPN/private subnets/reverse proxies), enforce non-root execution, rotate credentials, and monitor suspicious WebSocket/terminal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.