Securityaffairs.Co Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
Article Content
- •The Marimo RCE vulnerability was exploited within 10 hours of its disclosure.
- •Attackers gained full control of systems via unauthenticated access to a specific WebSocket endpoint.
- •Sensitive credentials were stolen in under three minutes during the exploitation process.
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability, tracked as CVE-2026-39987, allows unauthenticated attackers to gain full control of affected Marimo instances by connecting to the terminal WebSocket endpoint (/terminal/ws) without any credentials. The flaw affects all versions prior to 0.23.0, with a CVSS score of 9.3. Attackers were able to execute arbitrary commands and exfiltrate sensitive information, including AWS access keys, in under three minutes. The rapid exploitation indicates that threat actors are actively monitoring vulnerability disclosures for even niche software. Marimo has approximately 20,000 GitHub stars and is primarily used by data scientists and developers. Users are advised to upgrade to version 0.23.0 immediately to mitigate the risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track CVE-2026-39987 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Human Attacker Exploits Marimo RCE at Machine Speed A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven…