Marimo
This hub aggregates every CVE we track for Marimo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
1
Critical
1
High
1
In CISA KEV
Severity distribution
MEDIUM2HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
2
0
1
0
2
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Marimo.
- CVE-2026-75149marimo < 0.23.15 Code Injection via MCP Server Configuration8.8
- CVE-2026-67618marimo < 0.23.15 API Key Exfiltration via Malicious Notebook PEP-723 Metadata6.5
- CVE-2026-54386marimo < 0.23.9 XSS via file Query Parameter in assets.py6.1
- CVE-2026-39987marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassKEV9.8
- GHSA-2679-6mx9-h9xcMarimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
- GHSA-xjv7-6w92-42r7marimo vulnerable to proxy abuse of /mpl/{port}/
Product normalization is registry-driven with AI assist and human review. How it works