Junglewise Threat Intelligence

CVE-2026-67618: marimo configuration injection via PEP-723 metadata

CVE-2026-67618 · Severity: medium · CVSS 6.5 · Published 2026-08-04

Technologies: Marimo. Vendors: Marimo.

Executive brief

marimo is an open-source interactive notebook platform. A configuration injection vulnerability allows notebook authors to steal API keys from operators who open malicious notebooks. When an operator opens a crafted notebook and attempts to use AI features, marimo sends their OpenAI API key to an attacker-controlled server, bypassing the need for any malicious code execution.

Technical details

The vulnerability is a configuration injection flaw in marimo's PEP-723 inline script metadata handling. The root cause is insufficient sanitization in the `sanitize_pyproject_dict` function, allowing attackers to embed a malicious `base_url` in notebook metadata. This attacker-controlled URL is merged into the session configuration with higher precedence than operator settings, causing marimo to send API requests to the attacker's endpoint while using the operator's `OPENAI_API_KEY` environment variable for authentication. The attack requires the operator to open the malicious notebook and make an AI request, but does not require explicit cell execution. A patch was released in marimo 0.23.15 implementing additional PEP-723 sanitization and a configuration allowlist.

Affected products

  • marimo marimo before 0.23.15

Timeline

  • 2026-08-04: disclosed: CVE-2026-67618 published
  • 2026-07-23: patched: Fix merged in commit 1a21bd7

References

Related threats