CVE-2026-39987: critical vulnerability in marimo-team marimo
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
marimo notebook application has a critical flaw where its terminal feature can be accessed without authentication, allowing attackers to run any command on the server. This bypasses all security protections that should prevent unauthorized access.
The /terminal/ws WebSocket endpoint lacks authentication validation, accepting unauthenticated connections that provide full PTY shell access. Unlike properly protected endpoints that invoke validate_auth(), this endpoint only verifies running mode and platform compatibility, enabling pre-authentication remote code execution on the underlying system.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.