CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Description
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploiteden·The Hacker News· Exploited Langflow knaithe
- Китайский хакер использовал DeepSeek для проведения автономных атакru-ru·Хакер (xakep.ru)· Exploited Langflow knaithe
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksen·The Hacker News· Exploited Langflow knaithe
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Storiesen·The Hacker News· Roundup xplogs22 phishing
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacksen-us·Palo Alto Unit 42· PoC Hermes Agent knaithe
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokensen·The Hacker News· Research ComfyUI malware
- Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Modelsen·The Hacker News· PoC open-weight LLM ai-ml
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploiten·The Hacker News· Exploited Marimo ai-ml
- 13th April – Threat Intelligence Reporten-us·Check Point Research· Exploited Bitcoin Depot wallets/crypto-ATM systems Qilin
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-39987 and every CVE in our database. Create a free account — no credit card required.
Create Free Account