Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure

Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure

First seen 9 Jun 2026, 22:29 UTC Hiveprowebflow.sysdig.com 91% similarity 72.8

Article Content

Browse articles
ThreatCluster

On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a full interactive shell via the /terminal/ws WebSocket endpoint. Exploitation was observed within 9 hours and 41 minutes of the advisory's publication, with attackers executing credential theft operations shortly after. The vulnerability affects all Marimo versions prior to 0.23.0 and has a CVSS score of 9.3. Researchers noted that no public proof-of-concept code existed at the time of the attack, indicating that attackers were able to construct exploits directly from the advisory's technical details. The attack pattern suggests professional threat actor involvement, focusing on credential harvesting rather than deploying malware. Organizations using Marimo are urged to implement emergency remediation to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-39987 allows unauthenticated RCE on Marimo instances via WebSocket. • Exploitation occurred within 9 hours and 41 minutes of the vulnerability disclosure. • Attackers focused on credential theft, highlighting the need for immediate remediation.

ThreatCluster AI

Timeline

2026-03-20
CVE-2026-33017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-08
CVE-2026-39987 disclosed
A critical RCE vulnerability in Marimo was publicly disclosed, affecting all versions prior to 0.23.0.
webflow.sysdig.com
2026-04-09
First exploitation attempt observed
Within 9 hours and 41 minutes of the advisory, the first exploitation attempt was detected by Sysdig TRT.
webflow.sysdig.com
2026-04-13
First public PoC released
The first public proof-of-concept code for CVE-2026-39987 was made available, aiding defenders.
Hivepro
2026-04-23
CVE-2026-39987 added to CISA KEV
CISA included CVE-2026-39987 in its Known Exploited Vulnerabilities catalog due to active exploitation.
Hivepro

Community

Browse all →