Marimo CVE-2026-39987: Pre-Auth RCE in AI Notebook Exploited Within 10 Hours of Disclosure
The Hacker News·high signal
Critical pre-auth RCE (CVSS 9.3) in the Marimo Python notebook's terminal WebSocket endpoint /terminal/ws, which skips authentication validation entirely. Sysdig recorded the first in-the-wild exploit just 9 hours 41 minutes after advisory publication — attacker built a working exploit from the advisory alone. Compromised AI notebooks typically expose API keys for OpenAI, Anthropic, Google, and cloud credentials.