logo

Critical Marimo pre-auth RCE flaw now under active exploitation

ID: 9682efff-38e5-51a3-935e-c65f3a8287c2

STIX ID: report--9682efff-38e5-51a3-935e-c65f3a8287c2

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2026-04-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical unauthenticated RCE (CVE-2026-39987, CVSS 9.3) in Marimo allowed remote access to an interactive shell via the /terminal/ws WebSocket; attackers began scanning and exploiting the flaw within 10–12 hours of public disclosure, conducting quick, manual credential thefts (exfiltrating .env variables and SSH keys). Marimo released version 0.23.0 to fix the issue and users are advised to upgrade immediately, block or disable /terminal/ws, restrict external access, and rotate exposed secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.