Junglewise Threat Intelligence

CVE-2026-54386: marimo XSS via file query parameter in notebook page

CVE-2026-54386 · Severity: medium · CVSS 6.1 · Published 2026-06-17

Technologies: Marimo-Team Marimo. Vendors: PyPI.

Executive brief

marimo is an interactive Python notebook used for data science and development. A security vulnerability in the notebook interface allows an attacker to trick a user into clicking a malicious link, which then executes unauthorized code in the user's browser. This could allow an attacker to steal sensitive information or perform actions on behalf of the user within the marimo application.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in marimo's notebook page due to improper escaping of single quotes in the 'file' query parameter. This parameter is reflected into an inline JavaScript string literal within the service worker injection logic in 'assets.py'. An unauthenticated attacker can craft a malicious URL using a payload starting with '__new__' to bypass internal 404 checks and execute arbitrary JavaScript in the context of the victim's marimo server origin. The execution occurs without Content-Security-Policy (CSP) restrictions. The issue is fixed in version 0.23.9 by properly escaping the user-controlled file_key.

Affected products

  • marimo-team marimo before 0.23.9

Timeline

  • 2026-06-04: patched: Fix merged in pull request #9789 and released in version 0.23.9
  • 2026-06-17: disclosed: Vulnerability published by VulnCheck and NVD

References

Related threats