← Back to CVE List
Vulnerability Intelligence Report
marimo < 0.23.15 Code Injection via MCP Server Configuration

CVE-2026-75149

x_open-source

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.64%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-94 ↗Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
marimo-team marimo 0 < 0.23.15 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.637%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulnCheck · Bug Bounty Provider · USA
Reserved2026-08-17T18:39:57
Published2026-08-19T17:48:46
Patch Date2026-08-19
Last Updated2026-08-21T19:41:11

LINK COPIED TO CLIPBOARD