Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
ID: 50668daa-2194-5e11-bc5d-6ef7b1d530c3
STIX ID: report--50668daa-2194-5e11-bc5d-6ef7b1d530c3
Feed Name: securityonline.info
A critical unauthenticated remote code execution vulnerability (CVE-2026-39987, CVSS 9.3) in marimo allows attackers to connect to an unprotected /terminal/ws WebSocket, trigger pty.fork(), and obtain a full interactive shell—often running as root in default Docker deployments. Exploitation was observed in the wild within ~9 hours and 41 minutes of the advisory, with operators quickly harvesting .env files, SSH keys, and AWS credentials; immediate patching to version 0.23.0+ or disabling/restricting the terminal endpoint and credential rotation are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
