Executive brief
Marimo, a Python-based interactive notebook used for data science and development, contains a critical security flaw that allows unauthorized users to take control of the host system. By accessing a specific web address used for terminal communications, an attacker can bypass all security checks and execute commands as if they were a legitimate user. This could lead to the theft of sensitive data, installation of malware, or complete disruption of the development environment.
Technical details
A remote code execution (RCE) vulnerability exists in Marimo due to missing authentication (CWE-306) on the /terminal/ws WebSocket endpoint. While other endpoints correctly implement the validate_auth() function, the terminal endpoint only verifies the running mode and platform support before establishing a connection. An unauthenticated attacker can connect to this endpoint over the network to obtain a full pseudo-terminal (PTY) shell. This allows for arbitrary command execution with the privileges of the Marimo process. The vulnerability has been observed being exploited in the wild and is addressed in version 0.23.0.
Affected products
- marimo-team marimo < 0.23.0
Timeline
- 2026-04-09: disclosed: Initial disclosure by GitHub, Inc.
- 2026-04-23: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2026-04-23: patched: Fix confirmed in version 0.23.0