Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39987

98
FAUCET Score

Marimo is a reactive Python notebook application that contains a critical pre-authentication remote code execution vulnerability in versions prior to 0.23.0. The terminal WebSocket endpoint /terminal/ws fails to properly validate user authentication, allowing unauthenticated attackers to establish connections and obtain shell access. This vulnerability affects the core functionality of the marimo application, impacting any deployment where the affected versions are in use. The vulnerability has a high FAUCET Risk Score of 87.0/100 and presents a severe threat due to its unauthenticated attack vector and minimal complexity requirements. An attacker can exploit this flaw without any credentials or authentication tokens, directly connecting to the terminal endpoint to execute arbitrary system commands with the privileges of the marimo process. The lack of authentication checks means any network-accessible marimo instance running an affected version is immediately exploitable. The vulnerability is actively being exploited in the wild and has been designated for inclusion on the Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed real-world exploitation activity. This high-visibility status combined with the straightforward nature of the attack makes prompt patching to version 0.23.0 or later a critical priority for all marimo users and organizations operating this software.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.23.0CPE matchmatch criteria
cpe:2.3:a:coreweave:marimo:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 4.0

9.3CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
95.34%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Apr 23, 2026
Nuclei: CVE-2026-39987 · Apr 9, 2026
This CVE's current EPSS score of 0.9534 is in the 99th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: marimoFixed in: 0.23.0

Vendor Advisories (1)

pipGHSA-2679-6mx9-h9xccritical

Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

Apr 8, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
sysdig.com / blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours
ExploitThird Party Advisory
github.com / marimo-team/marimo/commit/c24d4806398f30be6b12acd6c60d1d7c68cfd12a
Patch
github.com / marimo-team/marimo/pull/9098
Issue TrackingPatch
github.com / marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc
ExploitMitigationVendor Advisory