Known vulnerability record

CVE-2026-39987

Marimo Remote Code Execution Vulnerability

Stable IDcve:CVE-2026-39987Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Marimo Remote Code Execution Vulnerability

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Keep the signals separate

CVSS severitycriticalScore 9.3 · source GitHub_M
EPSS probability96.6%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-23
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-04-09
CVE modified
2026-04-24
KEV date added
2026-04-23
Dataset fetched
2026-08-21T03:55:06.647Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.