Critical Marimo pre-auth RCE flaw now under active exploitation
ID: 9682efff-38e5-51a3-935e-c65f3a8287c2
STIX ID: report--9682efff-38e5-51a3-935e-c65f3a8287c2
Feed Name: Bleeping Computer
A critical unauthenticated RCE (CVE-2026-39987, CVSS 9.3) in Marimo allowed remote access to an interactive shell via the /terminal/ws WebSocket; attackers began scanning and exploiting the flaw within 10–12 hours of public disclosure, conducting quick, manual credential thefts (exfiltrating .env variables and SSH keys). Marimo released version 0.23.0 to fix the issue and users are advised to upgrade immediately, block or disable /terminal/ws, restrict external access, and rotate exposed secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
