logo

Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint

ID: 50668daa-2194-5e11-bc5d-6ef7b1d530c3

STIX ID: report--50668daa-2194-5e11-bc5d-6ef7b1d530c3

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2026-39987, CVSS 9.3) in marimo allows attackers to connect to an unprotected /terminal/ws WebSocket, trigger pty.fork(), and obtain a full interactive shell—often running as root in default Docker deployments. Exploitation was observed in the wild within ~9 hours and 41 minutes of the advisory, with operators quickly harvesting .env files, SSH keys, and AWS credentials; immediate patching to version 0.23.0+ or disabling/restricting the terminal endpoint and credential rotation are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.