#MarimoExploit
A critical unauthenticated RCE in Marimo (CVE-2026-39987) was exploited just 9 hours after public disclosure via the terminal WebSocket endpoint, allowing shell access and data exfiltration. Upgrade to 0.23.0+. #MarimoExploit #RCEvulnerability
Critical Marimo Flaw Exploited Hours After Public Disclosure
A threat actor built a working exploit for a critical unauthenticated RCE in Marimo (CVE-2026-39987) and began weaponizing it roughly nine hours after the bug’s public disclosure. The attacker used the unauthenticated terminal WebSocket endpoint to gain an interactive shell, quickly exfiltrated credential files and searched for SSH keys; users should...
www.hendryadrian.com
April 10, 2026 at 10:45 AM