CVE-2026-39987
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Description
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.
In plain language
AI Act nowMarimo versions before 0.23.0 can let anyone on the network log in without credentials and run commands on the server—this is an immediate, high-risk issue if you use Marimo’s terminal feature.
CVE-2026-39987 is a pre-auth remote code execution in Marimo where the terminal WebSocket endpoint bypasses authentication checks, allowing unauthenticated attackers to establish a terminal session and execute arbitrary system commands.
What to do now
- Check whether your Marimo deployment is running a version earlier than 0.23.0 and whether the terminal functionality is enabled.
- Upgrade Marimo to 0.23.0 (or a later release) to remove the unauthenticated terminal WebSocket command-execution path.
- If you cannot upgrade right away, temporarily disable the terminal feature or block access to the terminal WebSocket endpoint from untrusted networks (e.g., the public internet), then plan the upgrade immediately.
- After updating, review server logs and alerts for signs of command execution attempts or unusual outbound connections from the Marimo host.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Secondsen·The Hacker News· Exploited Marimo rce
- Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Modeen·The Hacker News· Patch Marimo Notebook Software ai-ml
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploiteden·The Hacker News· Exploited Langflow knaithe
- Китайский хакер использовал DeepSeek для проведения автономных атакru-ru·Хакер (xakep.ru)· Exploited Langflow knaithe
- Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacksen·The Hacker News· Exploited Langflow knaithe
- ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Storiesen·The Hacker News· Roundup xplogs22 phishing
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacksen-us·Palo Alto Unit 42· PoC Hermes Agent knaithe
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokensen·The Hacker News· Research ComfyUI malware
- Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Modelsen·The Hacker News· PoC open-weight LLM ai-ml
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploiten·The Hacker News· Exploited Marimo ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-39987 and every CVE in our database. Create a free account — no credit card required.
Create Free Account