criticalSecurity flaw UnknownPublish anonymously
Marimo Pre-Auth RCE (CVE-2026-39987)
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
CVSS 9.3. Marimo Python reactive notebook (~19.6k GitHub stars) terminal WebSocket endpoint `/terminal/ws` lacks authentication. Single WebSocket connection grants full PTY shell. Commonly runs as root in Docker. Sysdig honeypots observed exploitation within hours of disclosure. Confirmed exploited in the wild. Fixed in v0.23.0.