Vulnerability  ·  2026-04-14

CVE-2026-39987: Pre-Auth RCE in Marimo Python Notebook

VulnerabilityHigh impactCVE-2026-39987
Marimo <0.23.0 exposes an unauthenticated terminal WebSocket endpoint, enabling unauthenticated remote code execution on hosts running notebooks — common in AI/ML development workflows.
Network, low complexity. Attacker connects to the exposed WebSocket and issues shell commands.
Marimo <0.23.0 with network-reachable WebSocket endpoints.
Upgrade to 0.23.0+. Restrict WebSocket access; segment dev environments; monitor anomalous WebSocket connections.
Sources
Cloud Security Alliance research note
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →