Marimo Vulnerability Under Active Exploit for Credential Theft

Marimo Vulnerability Under Active Exploit for Credential Theft

A critical pre-authentication remote code execution (RCE) vulnerability in the open-source reactive Python notebook platform, Marimo, is currently being actively exploited. Cyber Threat Intelligence reports indicate that attackers began leveraging this flaw, tracked as CVE-2026-39987, mere hours after its public disclosure. The vulnerability affects Marimo versions 0.20.4 and earlier, and has been assigned a critical severity score of 9.3 by GitHub.

According to cloud-security firm Sysdig, threat actors developed an exploit based on information from the developer’s advisory and immediately deployed it in attacks aimed at credential theft. The root cause is identified as an insecure WebSocket endpoint (β€˜/terminal/ws’) that exposes an interactive terminal without adequate authentication. This allows unauthenticated clients to gain direct access to a full interactive shell, operating with the same privileges as the Marimo process.

Marimo developers released version 0.23.0 on April 9th to patch this vulnerability. The issue primarily impacts users who deployed Marimo as an editable notebook or exposed it to a shared network using the --host 0.0.0.0 flag while in edit mode. Sysdig observed significant reconnaissance activity within 12 hours of disclosure, with initial exploitation attempts targeting credential theft occurring in under 10 hours.

What This Means For You

  • Rated critical severity β€” prioritize patching or mitigation.
  • New vulnerability disclosed β€” verify if your stack is exposed.
πŸ”Ž
Turn this CVE into SIEM detection coverage Generate detection rules for Splunk, Sentinel, QRadar & Elastic β€” straight from this vulnerability. Use /detect in the Intel Bot.
Open Intel Bot β†’
Source & Attribution
Source PlatformTelegram
ChannelCyber Threat Intelligence
PublishedApril 12, 2026 at 17:34 UTC

This content was AI-rewritten and enriched by Shimi's Cyber World based on the original source. All intellectual property rights remain with the original author.

Believe this infringes your rights? Submit a takedown request.

Related coverage

Dutch Authorities Dismantle Botnet of 17 Million Infected Devices

Dutch authorities, in collaboration with the Dutch Politie and the National Cyber Security Center (NCSC), have successfully dismantled a massive botnet, according to The Hacker...

threat-intelvulnerabilitymalware
/SCW Vulnerability Desk /MEDIUM /⚑ 3 IOCs

Flowise RCE Exploit Code Publicly Released

Exploit code for a critical one-click Remote Code Execution (RCE) vulnerability in Flowise has been publicly released, according to SecurityWeek. This flaw allows attackers to...

threat-intelvulnerability
/SCW Vulnerability Desk /MEDIUM /⚑ 1 IOC /⚙ 3 Sigma

OpenAI ChatGPT Vulnerability: ChatGPhish Turns Summaries Into Phishing Surface

The Hacker News reports a critical vulnerability in OpenAI's ChatGPT, dubbed 'ChatGPhish' by Permiso Security. This technique exploits ChatGPT's implicit trust in Markdown links and...

threat-intelvulnerabilityphishingai-security
/SCW Vulnerability Desk /MEDIUM /⚑ 3 IOCs /⚙ 3 Sigma