CVE-2026-39987
KEVCRITICAL 9.8EPSS 97.3%
marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.
- CVSS v4.0
- 9.3 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v4.0
- 9.3 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 97.28% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2026-04-23
- Nuclei
- critical · CWE-306
- Published
- 2026-04-09
- Updated
- 2026-04-24
Proof-of-concept exploits (20)
- https://www.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitatio…
- advisories/GHSA-2679-6mx9-h9xc
- 0xBlackash/CVE-2026-399870★ · 2026-04-13
- fevar54/marimo_CVE-2026-39987_RCE_PoC0★ · 2026-04-13
- h3raklez/CVE-2026-399871★ · 2026-04-25
- M3PH1569/CVE-2026-39987-POC3★ · 2026-07-19
- 0xdeadroot/CVE-2026-39987-marimo-rce0★ · 2026-05-16
- HORKimhab/CVE-2026-399870★ · 2026-05-30
- vanhari/CVE-2026-399870★ · 2026-08-02
- jasonbernier/CVE-2026-399870★ · 2026-08-04
- gbuyssens/CVE-2026-399870★ · 2026-08-02
- matesz44/cve-2026-399870★ · 2026-08-12
- alreadyClosed/CVE-2026-399870★ · 2026-08-07
- K3ysTr0K3R/CVE-2026-399871★ · 2026-08-22
- dodeepsink/CVE-2026-39987.py0★ · 2026-08-23
- MADA0L/CVE-2026-39987-Poc0★ · 2026-08-10
- Wind010/CVE-2026-39987_PoC1★ · 2026-08-03
- Nxploited/CVE-2026-39987
- mki9/CVE-2026-39987_exploit
- snehil00121/Public_CVEs_Exploit