Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
ID: 58270638-6d3c-5e31-ac09-3e8fa5898f07
STIX ID: report--58270638-6d3c-5e31-ac09-3e8fa5898f07
Feed Name: The Hacker News
Threat Score
Marimo released a patch (v0.23.15) for CVE-2026-75149, a high-severity code-injection vulnerability in notebook metadata that could launch attacker-controlled MCP commands as local subprocesses when a malicious notebook is opened in edit mode (CVSS v4 8.7 / v3.1 8.8); users on affected versions prior to 0.23.15 are advised to upgrade to a non-vulnerable release.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
