Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
The Hacker News | #1 Trusted Source for Cybersecurity News [Uno…
April 10, 2026
A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including
Discussion in the ATmosphere