marimo A.I CyberSecurity Scoring
marimo
Company Information
Website:https://marimo.io
Employees number:12
Number of followers:613
NAICS:5112
Industry Type:Software Development
Homepage:marimo.io
marimo Risk Score (AI oriented)
Between 700 and 749
marimoSoftware Development
Updated:
19/05/2026
19/05/2026
727/1000
Moderate
Ba
marimo Global Score (TPRM)
xxxx
marimoSoftware Development
Score locked

marimoModerate
Current Score
727Ba (MODERATE)
01000
2 incidents
-11.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
728
MAY 2026
748
Cyber Attack
19 May 2026 • marimo
Hugging Face and Marimo: Critical Marimo Security Vulnerability Enables Remote Code Execution Attacks
Critical Marimo Python Notebook Vulnerability Exploited for Remote Code Execution
727
CRITICAL-21
MARHUG1779193669
Critical Marimo Python Notebook Vulnerability Exploited for Remote Code Execution
A severe security flaw in the Marimo Python notebook framework (CVE-2026-39987) is being actively exploited to achieve pre-authentication remote code execution (RCE), granting attackers full control over vulnerable systems. The vulnerability stems from a missing authentication check in the `/terminal/ws` WebSocket endpoint, allowing unauthenticated attackers to spawn system-level shells without credentials.
### Key Details
- Affected Versions: Marimo ≤ 0.22.x
- Exploitation Method: Attackers connect to `ws://target:2718/terminal/ws`, bypassing authentication and gaining interactive shell access.
- Active Threats: The flaw is being weaponized to deploy NKAbuse malware, with payloads hosted on Hugging Face Spaces, a popular AI/ML platform.
- Impact: Successful exploitation enables full system compromise, data theft (API keys, credentials, proprietary AI models), lateral movement, and persistence via cron jobs or container escapes.
### Technical Breakdown
The vulnerability arises from inconsistent authentication enforcement while most Marimo endpoints are protected, the `/terminal/ws` WebSocket endpoint lacks access controls, directly spawning a pseudo-terminal (`pty.fork()`) upon connection. A simple Python exploit can execute arbitrary commands, turning the instance into a remotely accessible terminal.
### Broader Risks
Marimo is widely used in AI/ML prototyping, data science, and internal analytics, often in cloud or containerized environments with access to sensitive resources. A single breach can escalate into a broader infrastructure compromise, particularly in trusted internal networks.
### Mitigation
- Upgrade to Marimo 0.23.0 or later to patch the flaw.
- Restrict network exposure via VPNs or authenticated reverse proxies.
- Run containers as non-root and limit privileges.
- Monitor for suspicious WebSocket activity and shell spawning.
The incident highlights the growing abuse of legitimate AI platforms for malware distribution and underscores the need for strict authentication enforcement in WebSocket endpoints.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
750
Vulnerability
08 Apr 2026 • marimo
Marimo and Sysdig: Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure
Critical Marimo RCE Vulnerability Exploited Within Hours of Disclosure
748
CRITICAL-2
MARSYS1776075943
Critical Marimo RCE Vulnerability Exploited Within Hours of Disclosure
A severe remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was actively exploited just 9 hours and 41 minutes after its public disclosure on April 8, 2026. Tracked as CVE-2026-39987 (CVSS 9.3), the flaw allows unauthenticated attackers to gain a full interactive shell on exposed instances.
The vulnerability affects Marimo versions 0.20.4 and earlier, specifically targeting the /terminal/ws WebSocket endpoint, which lacks proper authentication checks. Unlike other endpoints, this path fails to validate user sessions, enabling attackers to establish a persistent shell with the privileges of the Marimo process without requiring credentials or complex payloads.
Security firm Sysdig detected the first exploitation attempts using honeypot servers. The attack began with an automated script to confirm RCE, followed by a human operator manually navigating the victim’s filesystem. Within three minutes, the attacker extracted a .env file containing sensitive cloud credentials, including AWS access keys.
Notably, no public proof-of-concept (PoC) exploit existed at the time, suggesting threat actors rapidly weaponized the flaw using details from the advisory potentially leveraging AI to accelerate exploit development. The incident underscores a growing trend of attackers targeting niche software, not just mainstream platforms.
Marimo, used by data scientists and AI researchers, has ~20,000 GitHub stars. The patched version (0.23.0) closes the vulnerable endpoint, but organizations are advised to review logs for unauthorized access and rotate exposed credentials.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
AUGUST 2025
750
JULY 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for marimo ??
What was marimo's A.I Rankiteo Cyber Score in May 2026 ??
What was marimo's A.I Rankiteo Cyber Score in April 2026 ??
What was marimo's A.I Rankiteo Cyber Score in March 2026 ??
What was marimo's A.I Rankiteo Cyber Score in February 2026 ??
What was marimo's A.I Rankiteo Cyber Score in January 2026 ??
What was marimo's A.I Rankiteo Cyber Score in December 2025 ??
What was marimo's A.I Rankiteo Cyber Score in November 2025 ??
What was marimo's A.I Rankiteo Cyber Score in October 2025 ??
What was marimo's A.I Rankiteo Cyber Score in September 2025 ??
What was marimo's A.I Rankiteo Cyber Score in August 2025 ??
What was marimo's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on marimo's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with marimo ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view marimo's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?