BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Marimo Critical Flaw Exploited in Under 10 Hours

Critical Marimo flaw exploited within ten hours, granting attackers full system access.

  • A critical security vulnerability (CVE-2026-39987) in the open-source Python notebook Marimo was exploited within 9 hours and 41 minutes of public disclosure.
  • The flaw allowed unauthenticated attackers to obtain a full system shell and execute arbitrary commands on any exposed instance, bypassing authentication.
  • The first observed attack involved manual reconnaissance to harvest credentials from the .env file and search for SSH keys, but no additional malware was deployed.
  • Attackers built a working exploit directly from the advisory description, demonstrating the shrinking window for defenders to apply critical patches.

In a stark demonstration of modern cyber threat velocity, a critical flaw in the Marimo data science notebook was weaponized by attackers less than 10 hours after its public disclosure on April 10, 2026, according to findings from Sysdig. The vulnerability, a pre-authenticated remote code execution bug tracked as CVE-2026-39987 with a CVSS score of 9.3, impacted all versions up to and including 0.20.4.

- Advertisement -

Maintainers stated in an advisory that the terminal WebSocket endpoint completely skipped authentication verification. Consequently, an unauthenticated attacker could connect and obtain a full interactive PTY shell to execute arbitrary system commands.

Sysdig’s honeypot recorded the first exploitation attempt just 9 hours and 41 minutes post-disclosure, even without public proof-of-concept code. The unknown threat actor manually explored the file system and systematically attempted to harvest data, notably targeting the .env file and SSH keys.

The attacker returned to the compromised system an hour later to access stolen data and check for other malicious activity. Meanwhile, no other payloads like cryptocurrency miners or backdoors were installed during these sessions.

This rapid exploitation highlights how threat actors closely monitor vulnerability disclosures. The incident proves that any internet-facing application with a critical advisory is a target, regardless of its popularity.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading