Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
marimo

marimo Vendor Cyber Rating & Cyber Score

marimo.io

We build next-generation Python tools for ML and data science, starting with the marimo notebook: explore data, build tools, and deploy apps in one seamless environment. The marimo notebook is free and open source — pip install marimo to get started today! Visit our repo to learn more: https://github.com/marimo-team/marimo


marimo A.I CyberSecurity Scoring

marimo
Company Information
Website:https://marimo.io
Employees number:12
Number of followers:613
NAICS:5112
Industry Type:Software Development
Homepage:marimo.io
marimo Risk Score (AI oriented)
Between 700 and 749
logo
marimoSoftware Development
Updated:
19/05/2026
727/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
marimo Global Score (TPRM)
xxxx
logo
marimoSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

marimo
marimoModerate
Current Score
727Ba (MODERATE)
01000
2 incidents
-11.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
728Before Incident
MAY 2026
748Before Incident
Cyber Attack
19 May 2026marimo
Hugging Face and Marimo: Critical Marimo Security Vulnerability Enables Remote Code Execution Attacks

Critical Marimo Python Notebook Vulnerability Exploited for Remote Code Execution

727After Incident
CRITICAL-21
MARHUG1779193669
Critical Marimo Python Notebook Vulnerability Exploited for Remote Code Execution A severe security flaw in the Marimo Python notebook framework (CVE-2026-39987) is being actively exploited to achieve pre-authentication remote code execution (RCE), granting attackers full control over vulnerable systems. The vulnerability stems from a missing authentication check in the `/terminal/ws` WebSocket endpoint, allowing unauthenticated attackers to spawn system-level shells without credentials. ### Key Details - Affected Versions: Marimo ≤ 0.22.x - Exploitation Method: Attackers connect to `ws://target:2718/terminal/ws`, bypassing authentication and gaining interactive shell access. - Active Threats: The flaw is being weaponized to deploy NKAbuse malware, with payloads hosted on Hugging Face Spaces, a popular AI/ML platform. - Impact: Successful exploitation enables full system compromise, data theft (API keys, credentials, proprietary AI models), lateral movement, and persistence via cron jobs or container escapes. ### Technical Breakdown The vulnerability arises from inconsistent authentication enforcement while most Marimo endpoints are protected, the `/terminal/ws` WebSocket endpoint lacks access controls, directly spawning a pseudo-terminal (`pty.fork()`) upon connection. A simple Python exploit can execute arbitrary commands, turning the instance into a remotely accessible terminal. ### Broader Risks Marimo is widely used in AI/ML prototyping, data science, and internal analytics, often in cloud or containerized environments with access to sensitive resources. A single breach can escalate into a broader infrastructure compromise, particularly in trusted internal networks. ### Mitigation - Upgrade to Marimo 0.23.0 or later to patch the flaw. - Restrict network exposure via VPNs or authenticated reverse proxies. - Run containers as non-root and limit privileges. - Monitor for suspicious WebSocket activity and shell spawning. The incident highlights the growing abuse of legitimate AI platforms for malware distribution and underscores the need for strict authentication enforcement in WebSocket endpoints.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: API keys, credentials, proprietary AI modelsSystems Affected: Marimo Python notebook framework (≤ 0.22.x)Operational Impact: Full system compromise, lateral movement, persistence via cron jobs or container escapes
DATA BREACH
Type Of Data Compromised: API keys, credentials, proprietary AI modelsSensitivity Of Data: High
APRIL 2026
750Before Incident
Vulnerability
08 Apr 2026marimo
Marimo and Sysdig: Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure

Critical Marimo RCE Vulnerability Exploited Within Hours of Disclosure

748After Incident
CRITICAL-2
MARSYS1776075943
Critical Marimo RCE Vulnerability Exploited Within Hours of Disclosure A severe remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was actively exploited just 9 hours and 41 minutes after its public disclosure on April 8, 2026. Tracked as CVE-2026-39987 (CVSS 9.3), the flaw allows unauthenticated attackers to gain a full interactive shell on exposed instances. The vulnerability affects Marimo versions 0.20.4 and earlier, specifically targeting the /terminal/ws WebSocket endpoint, which lacks proper authentication checks. Unlike other endpoints, this path fails to validate user sessions, enabling attackers to establish a persistent shell with the privileges of the Marimo process without requiring credentials or complex payloads. Security firm Sysdig detected the first exploitation attempts using honeypot servers. The attack began with an automated script to confirm RCE, followed by a human operator manually navigating the victim’s filesystem. Within three minutes, the attacker extracted a .env file containing sensitive cloud credentials, including AWS access keys. Notably, no public proof-of-concept (PoC) exploit existed at the time, suggesting threat actors rapidly weaponized the flaw using details from the advisory potentially leveraging AI to accelerate exploit development. The incident underscores a growing trend of attackers targeting niche software, not just mainstream platforms. Marimo, used by data scientists and AI researchers, has ~20,000 GitHub stars. The patched version (0.23.0) closes the vulnerable endpoint, but organizations are advised to review logs for unauthorized access and rotate exposed credentials.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
MOTIVATION
Credential theft, potential lateral movement
IMPACT
Data Compromised: AWS access keys, .env file contentsSystems Affected: Marimo instances (versions 0.20.4 and earlier)Operational Impact: Unauthorized access to sensitive credentials, potential cloud resource compromiseBrand Reputation Impact: Potential reputational damage due to rapid exploitation
DATA BREACH
Type Of Data Compromised: Cloud credentials (AWS access keys), environment variablesSensitivity Of Data: High (cloud infrastructure access)Data Exfiltration: Yes (.env file extracted).env
MARCH 2026
750Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for marimo ?
?
What was marimo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was marimo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was marimo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was marimo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was marimo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was marimo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was marimo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was marimo's A.I Rankiteo Cyber Score in October 2025 ?
?
What was marimo's A.I Rankiteo Cyber Score in September 2025 ?
?
What was marimo's A.I Rankiteo Cyber Score in August 2025 ?
?
What was marimo's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on marimo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with marimo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view marimo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?