CVE-2026-39987criticalunder attackCWE-306

CVE-2026-39987: critical vulnerability in marimo-team marimo

marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.3epss 38%
from disclosure to weapon3 days
Published on NVDApr 9
1st PoC+3d
CISA KEV+14d
exploitation probability
38%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
52 public exploit(s)
Action required by CISAfederal deadline: 2026-05-07

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

marimo notebook application has a critical flaw where its terminal feature can be accessed without authentication, allowing attackers to run any command on the server. This bypasses all security protections that should prevent unauthorized access.

Technical detail

The /terminal/ws WebSocket endpoint lacks authentication validation, accepting unauthenticated connections that provide full PTY shell access. Unlike properly protected endpoints that invoke validate_auth(), this endpoint only verifies running mode and platform compatibility, enabling pre-authentication remote code execution on the underlying system.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
marimo-team · marimo
public PoCs found — 52
exploitdbwww.exploit-db.com/exploits/52673unverifiedgithubgithub.com/Th3Purge/CVE-2026-39987★ 9githubgithub.com/M3PH1569/CVE-2026-39987-POC★ 5githubgithub.com/LaArana12/CVE-2026-39987-Marimo-Preauth-RCE★ 1githubgithub.com/keraattin/CVE-2026-39987★ 1githubgithub.com/Nxploited/CVE-2026-39987★ 1githubgithub.com/Wind010/CVE-2026-39987_PoC★ 1githubgithub.com/h3raklez/CVE-2026-39987★ 1githubgithub.com/rootdirective-sec/CVE-2026-39987-Lab★ 1githubgithub.com/Ghxstsec/CVE-2026-39987★ 1githubgithub.com/K3ysTr0K3R/CVE-2026-39987★ 1githubgithub.com/dodeepsink/CVE-2026-39987.py★ 0githubgithub.com/fevar54/marimo_CVE-2026-39987_RCE_PoC★ 0githubgithub.com/HORKimhab/CVE-2026-39987★ 0githubgithub.com/jasonbernier/CVE-2026-39987★ 0githubgithub.com/alreadyClosed/CVE-2026-39987★ 0githubgithub.com/MADA0L/CVE-2026-39987-Poc★ 0githubgithub.com/matesz44/cve-2026-39987★ 0githubgithub.com/mki9/CVE-2026-39987_exploit★ 0githubgithub.com/Dhiaelhak-Rached/CVE-2026-39987-lab-or-marimo-cve-lab★ 0githubgithub.com/0xdeadroot/CVE-2026-39987-marimo-rce★ 0githubgithub.com/gbuyssens/CVE-2026-39987★ 0githubgithub.com/vanhari/CVE-2026-39987★ 0githubgithub.com/iapetus12/cohort-htb★ 0githubgithub.com/stapat1245/CVE-2026-39987-PoC★ 0githubgithub.com/mfahdk/CVE-2026-39987_RCE_PoC★ 0githubgithub.com/jenniferreire26/CVE-2026-39987★ 0githubgithub.com/0xBlackash/CVE-2026-39987★ 0githubgithub.com/julichaan/CVE-2026-39987_POC★ 0vulncheckvulncheck.com/xdb/eb58a1ca472dunverifiedvulncheckvulncheck.com/xdb/81aa6bd64500unverifiedvulncheckvulncheck.com/xdb/9721bec3eec9unverifiedvulncheckvulncheck.com/xdb/b6679792fce1unverifiedvulncheckvulncheck.com/xdb/3e64d4c2f1b0unverifiedvulncheckvulncheck.com/xdb/159ecfd3663cunverifiedvulncheckvulncheck.com/xdb/dcb8d294ce37unverifiedvulncheckvulncheck.com/xdb/23c534c36ecfunverifiedvulncheckvulncheck.com/xdb/af608e5d982aunverifiedvulncheckvulncheck.com/xdb/7fdb630d05ecunverifiedvulncheckvulncheck.com/xdb/ac09a77ffe6aunverifiedvulncheckvulncheck.com/xdb/29eca270a4d1unverifiedvulncheckvulncheck.com/xdb/ab780c72bc27unverifiedvulncheckvulncheck.com/xdb/eb3968672d84unverifiedvulncheckvulncheck.com/xdb/7086cc332168unverifiedvulncheckvulncheck.com/xdb/3644ef9481ddunverifiedvulncheckvulncheck.com/xdb/d7fabac0bcefunverifiedvulncheckvulncheck.com/xdb/aed1f6e0a3b6unverifiedvulncheckvulncheck.com/xdb/e96ddf92787cunverifiedvulncheckvulncheck.com/xdb/19283faf713dunverifiedvulncheckvulncheck.com/xdb/8f63cbf5d0a2unverifiedvulncheckvulncheck.com/xdb/4796862bb4cdunverifiedvulncheckvulncheck.com/xdb/199f55da9f24unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.