Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
ID: 2748e5ed-1579-58f6-95a6-1b01dabf7fed
STIX ID: report--2748e5ed-1579-58f6-95a6-1b01dabf7fed
Feed Name: The Hacker News
A critical pre-auth remote code execution flaw (CVE-2026-39987, CVSS 9.3) in Marimo's /terminal/ws WebSocket endpoint allowed unauthenticated attackers to spawn a full PTY and execute arbitrary commands; Marimo fixed the issue in version 0.23.0. Sysdig observed exploitation within 9 hours 41 minutes of disclosure: an attacker connected to a honeypot, explored the filesystem, harvested .env contents and searched for SSH keys, and returned to confirm findings, though no miners or backdoors were installed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
