Marimo pre-auth WebSocket terminal RCE (CVE-2026-39987); CVSS 9.8 — exploited to AWS/SSH bastion
Marimo GHSA-2679-6mx9-h9xc / NVD: CVE-2026-39987 is a pre-authentication RCE in the reactive Python notebook server. The /terminal/ws WebSocket lacks auth, giving an unauthenticated attacker a full PTY shell. NVD: versions prior to 0.23.0 affected; CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CVSS 4.0 9.3 also published. Exploit-DB 52673 (2 Sep 2026) shipped a public PoC (cited ≤0.20.4). UPDATE 15 September 2026 (Sysdig Threat Research; THN wire): Sysdig observed a skilled human operator exploit this CVE within hours of disclosure, pivoting from Marimo to AWS Secrets Manager then an SSH bastion in eight seconds with a hand-rolled Python toolkit (850+ interactive commands over ~9 hours; source IP 172.236.12.17 on first WS connect). Upgrade to 0.23.0+; never expose Marimo terminal WebSockets to the internet. Primary: Marimo GHSA / NVD; research: Sysdig; wire: THN.
- Product
- Marimo reactive Python notebook server
- Versions
- Prior to 0.23.0 (NVD); EDB 52673 demonstrated ≤0.20.4. Fixed: 0.23.0+
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade Marimo to 0.23.0 or later; bind to localhost/VPN only; do not expose /terminal/ws publicly
Primary: Marimo GHSA-2679-6mx9-h9xc (CVE-2026-39987) · Vendor: NVD — CVE-2026-39987 (prior to 0.23.0; CVSS 9.8) · CVE: CVE-2026-39987 · Sysdig TRT — hand-rolled Marimo exploit to SSH bastion (THN 15 Sep wire)
