Feed/CVE-2026-39987
CVE-2026-39987CISA KEV: Actively Exploited

Marimo Remote Code Execution Vulnerability

Published Apr 23, 2026·Updated Apr 23, 2026

NVD Description

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Public Exploits & PoCs17 found

PoC: CVE-2026-39987

CVE-2026-39987 — Marimo Pre-Authentication RCE

1

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-39987_PoC

A proof-of-concept for CVE-2026-39987

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-39987

CVE-2026-39987 poc

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-39987

Simple POC for CVE-2026-39987

[POC] GHSA-8gj2-2cvc-6xx7 — CVE-2026-39987

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

[POC] CVE-2026-39987 — CVE-2026-39987

CVE-2026-39987 - Draft

[POC] CVE-2026-39987 — CVE-2026-39987-POC

CVE-2026-39987 Exploitation Tool - Marimo < 0.23.0 Pre-Auth RCE (WebSocket)

[POC] CVE-2026-39987 — CVE-2026-39987-marimo-rce

CVE-2026-39987

[POC] CVE-2026-39987 — CVE-2026-39987

Marimo Pre-Auth RCE

[POC] CVE-2026-39987 — CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

[POC] CVE-2026-39987 — CVE-2026-39987

CVE-2026-39987: Marimo Python Notebook Pre-Auth RCE (CVSS 9.3). Python & Nmap NSE detection scripts. Missing authentication on /terminal/ws WebSocket endpoint gives attackers a full PTY shell without any credentials. Exploited in the wild within 10 hours of disclosure. Fixed in Marimo 0.23.0.

PoC: CVE-2026-39987.py

This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive shell.

PoC: cve-2026-39987

CVE-2026-39987 PoC: Marimo<0.23.0 Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

PoC: CVE-2026-39987-Poc

Proof of Concept (PoC) WebSocket client for CVE-2026-39987 (Marimo Pre-Auth RCE), intended for authorized security testing.

PoC: CVE-2026-39987

CVE-2026-39987 for marimo 0.20.4 PoC

PoC: marimo_CVE-2026-39987_RCE_PoC

CVE-2026-39987 - Marimo < 0.23.0 Pre-Auth RCE (WebSocket) PoC de explotación - Conecta a /terminal/ws sin autenticación Author: Fevar54 Date: 2026-04-13 Severity: CRITICAL CVSS: 9.3

PoC: CVE-2026-39987

CVE-2026-39987

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free