Product
high
advisory
Remote Code Injection Vulnerability in marimo
1 TTP 1 CVEMarimo versions before 0.23.15 contain a command injection vulnerability in the notebook configuration handler, allowing arbitrary command execution when a malicious notebook is opened in edit mode.
marimo
1t
1c
critical
advisory
Marimo Pre-Authentication Remote Code Execution Vulnerability (CVE-2026-39987)
2 rules 1 TTP 1 CVECVE-2026-39987 is a pre-authentication remote code execution vulnerability in Marimo, enabling unauthenticated attackers to execute arbitrary system commands.
Marimo
CVE-2026-39987
rce
vulnerability
2r
1t
1c
critical
advisory
Marimo Pre-Auth RCE via Terminal WebSocket Authentication Bypass
1 rule 1 TTPMarimo versions 0.20.4 and earlier contain a pre-authentication remote code execution vulnerability in the `/terminal/ws` WebSocket endpoint, allowing unauthenticated attackers to execute arbitrary system commands, resulting in a full interactive root shell.
Marimo
rce
websocket
1r
1t