Executive brief
marimo is an open-source interactive notebook platform. A configuration injection vulnerability allows notebook authors to steal API keys from operators who open malicious notebooks. When an operator opens a crafted notebook and attempts to use AI features, marimo sends their OpenAI API key to an attacker-controlled server, bypassing the need for any malicious code execution.
Technical details
The vulnerability is a configuration injection flaw in marimo's PEP-723 inline script metadata handling. The root cause is insufficient sanitization in the `sanitize_pyproject_dict` function, allowing attackers to embed a malicious `base_url` in notebook metadata. This attacker-controlled URL is merged into the session configuration with higher precedence than operator settings, causing marimo to send API requests to the attacker's endpoint while using the operator's `OPENAI_API_KEY` environment variable for authentication. The attack requires the operator to open the malicious notebook and make an AI request, but does not require explicit cell execution. A patch was released in marimo 0.23.15 implementing additional PEP-723 sanitization and a configuration allowlist.
Affected products
- marimo marimo before 0.23.15
Timeline
- 2026-08-04: disclosed: CVE-2026-67618 published
- 2026-07-23: patched: Fix merged in commit 1a21bd7