Root in One Request: Marimo's Critical Pre-Auth RCE (CVE-2026-39987)
Blog post from Endor Labs
CVE-2026-39987 is a critical security vulnerability in Marimo, a popular Python reactive notebook framework, which allows remote code execution without authentication via a WebSocket endpoint. This vulnerability, rated 9.3 on the CVSS scale, stems from an inconsistency in WebSocket authentication, specifically in the terminal WebSocket endpoint that failed to enforce authentication while other endpoints did. This flaw has already been exploited in the wild, with Sysdig Threat Research Team observing exploitation attempts shortly after its disclosure. The issue was resolved in Marimo version 0.23.0, which closed the authentication gap by aligning the terminal WebSocket's authentication with other WebSocket routes. The vulnerability highlights the risks associated with exposing Marimo's edit mode to the internet, as it can be targeted for credential theft and unauthorized access to sensitive data. Users are urged to upgrade to the latest version, verify consistent WebSocket authentication, and treat notebook servers with high-security measures to prevent exploitation.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 2 | 1,821 | 338 | 111 | +22% |
| LLM | 1 | 5,932 | 1,046 | 223 | -2% |
| Real-time | 1 | 6,296 | 1,346 | 246 | -2% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.