top of page
perceptive_background_267k.jpg

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system comm…

Published:

23 april 2026 om 00:00:00

Alert date:

23 april 2026 om 18:00:49

Source:

cisa.gov

Click to open the original link from this advisory

Web Technologies

CVE-2026-39987 is a critical pre-authorization remote code execution vulnerability in Marimo that allows unauthenticated attackers to gain shell access and execute arbitrary system commands. This vulnerability poses a high security risk as it requires no authentication and can lead to complete system compromise. The vulnerability has been documented by CISA and tracked on GitHub security advisories. Given the nature of remote code execution without authentication requirements, this represents a severe security flaw that could be easily exploited by malicious actors. Organizations using Marimo should prioritize patching this vulnerability immediately.

Technical details

Mitigation steps:

Affected products:

Marimo

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page