← Back to CVE List
Vulnerability Intelligence Report
marimo Affected by Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
9.3
CRITICAL
EPSS Probability:95.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-306 ↗CWE-306: Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
marimo-team marimo < 0.23.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
95.645%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-04-08T00:01:47
Published2026-04-09T17:16:55
Last Updated2026-04-24T03:55:20

LINK COPIED TO CLIPBOARD