Marimo Vulnerability Under Active Exploit for Credential Theft

Marimo Vulnerability Under Active Exploit for Credential Theft

A critical pre-authentication remote code execution (RCE) vulnerability in the open-source reactive Python notebook platform, Marimo, is currently being actively exploited. Cyber Threat Intelligence reports indicate that attackers began leveraging this flaw, tracked as CVE-2026-39987, mere hours after its public disclosure. The vulnerability affects Marimo versions 0.20.4 and earlier, and has been assigned a critical severity score of 9.3 by GitHub.

According to cloud-security firm Sysdig, threat actors developed an exploit based on information from the developer’s advisory and immediately deployed it in attacks aimed at credential theft. The root cause is identified as an insecure WebSocket endpoint (‘/terminal/ws’) that exposes an interactive terminal without adequate authentication. This allows unauthenticated clients to gain direct access to a full interactive shell, operating with the same privileges as the Marimo process.

Marimo developers released version 0.23.0 on April 9th to patch this vulnerability. The issue primarily impacts users who deployed Marimo as an editable notebook or exposed it to a shared network using the --host 0.0.0.0 flag while in edit mode. Sysdig observed significant reconnaissance activity within 12 hours of disclosure, with initial exploitation attempts targeting credential theft occurring in under 10 hours.

What This Means For You

  • Rated critical severity — prioritize patching or mitigation.
  • New vulnerability disclosed — verify if your stack is exposed.
🔎
Turn this CVE into SIEM detection coverage Generate detection rules for Splunk, Sentinel, QRadar & Elastic — straight from this vulnerability. Use /detect in the Intel Bot.
Open Intel Bot →

Related Posts

JanaWare Ransomware: Turkish Citizens in the Crosshairs

The cybercriminal landscape is a constantly shifting beast, and new ransomware strains are always emerging. According to The Record by Recorded Future, a new player...

threat-inteldata-breachgovernmentmalwareransomwareidentity
/MEDIUM

Microsoft Patches SharePoint Zero-Day, 160 Vulnerabilities

Microsoft's latest Patch Tuesday was a big one, addressing a staggering 161 vulnerabilities. According to SecurityWeek, this makes it the second-largest Patch Tuesday ever, based...

threat-intelvulnerabilitymicrosoft
/MEDIUM

Microsoft Drops Windows 10 Extended Security Update

Microsoft has rolled out the Windows 10 KB5082200 extended security update, a critical patch addressing vulnerabilities initially slated for the April 2026 Patch Tuesday. According...

threat-inteldata-breachmalwarevulnerabilitymicrosofttools
/HIGH