CVE-2026-75149Patch

MEDIUMCVSS 8.7 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-08-25); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-08-25: 4Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Active Exploitation · 2026-08-25: 1Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-25: 4Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 108-2508-2708-28
Signal classification3 categories
Patch
466.7%
Active Exploitation
116.7%
General
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-254
Active Exploitation1General1Patch2
2026-08-271
Patch1
2026-08-281
Patch1
Full discourse6 posts
  • The Hacker News@TheHackersNews
    Patch

    ‼️ A Marimo notebook can launch MCP commands before cells run. CVE-2026-75149 triggers when a crafted notebook is opened in edit mode. It affects versions before 0.23.15. Marimo fixed it in 0.23.15. Read the details: https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html

    Post summary

    Marimo CVE-2026-75149 lets crafted notebooks launch MCP commands pre-cell execution; patch available in 0.23.15; no evidence of active exploitation or PoC.

    18040524.4K
    2.4M followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🔴 Marimo'da CVE-2026-75149: Kötü Amaçlı Notebook MCP Komutu Çalıştırabiliyor #OpenSouce Python notebook platformu #Marimo'da, özel hazırlanmış bir notebook dosyasının açılmasıyla saldırgan kontrollü MCP komutlarının yerel sistemde çalıştırılmasına izin veren bir güvenlik açığı keşfedildi. #VestraDAO #Brolyz #Orta CVE-2026-75149 olarak takip edilen açık, notebook edit modunda açıldığında, herhangi bir hücre çalıştırılmadan önce saldırganın belirlediği komutu yerel bir subprocess olarak çalıştırabiliyor. 🔴 CVSS 3.1: 8.8 - Yüksek Saldırı için kullanıcı etkileşimi gerekiyor ancak saldırganın kimlik doğrulaması yapmasına gerek bulunmuyor. Özellikle dikkat çekici nokta, saldırı zincirinin MCP (Model Context Protocol) yapılandırması üzerinden gerçekleşmesi. Kötü amaçlı notebook, saldırgan tarafından kontrol edilen bir MCP sunucu komutunu yapılandırma içine yerleştirebiliyor. 🛡️ Çözüm: Marimo 0.23.15 veya daha yeni bir sürüme güncellenmeli. Marimo'nun düzeltmesi, notebook metadata'sını güvenilmeyen veri olarak ele alıp MCP #gibi yapılandırma alanlarını allowlist yaklaşımıyla sınırlandırıyor. ⚠️ Özellikle internetten indirilen veya güvenilmeyen kaynaklardan alınan Marimo notebook dosyalarını açarken dikkatli olun. AI agent'ların ve MCP araçlarının yaygınlaşmasıyla birlikte, notebook #gibi geliştirici araçlarındaki güvenlik açıkları gibi yeni saldırı yüzeyleri de giderek önem kazanıyor.

    Post summary

    CVE‑2026‑75149 in the Marimo notebook platform allows arbitrary MCP command execution via a malicious notebook; CVSS 3.1 8.8. The recommended mitigation is updating to Marimo 0.23.15+, which restricts untrusted notebook metadata and configuration fields.

    0002033
    521 followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    ثغرة حقن كود عالية الخطورة في نوتبوك ماريمو تُتيح تنفيذ أوامر ضارة دون مصادقة عند فتح الملف. المعرّف : CVE-2026-75149 درجة الخطورة : 8.7 (CVSS v4) - High الإصدارات المتأثرة : Marimo < 0.23.15 الحل : Upgrade to v0.23.15 #Marimo #CVE202675149

    Post summary

    CVE-2026-75149 is a high‑severity code injection flaw in Marimo versions below 0.23.15 that permits unauthenticated execution of malicious commands; users should upgrade to v0.23.15.

    01000238
    39.9K followersView on X
  • Swif@swif_ai
    Patch

    Marimo patched CVE-2026-75149 (CVSS 8.7): a crafted notebook could run an attacker-set MCP command before any cell executed, no auth required. Treat notebook config as untrusted input, not settings. https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html

    Post summary

    Marimo has released a patch for CVE-2026-75149, a zero‑authentication RCE caused by malicious notebook configurations that run attacker‑set MCP commands before execution. The advisory provides the CVSS score and remediation guidance.

    0000075
    59 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis reveals attackers exploiting CVE-2026-75149 to inject malicious MCP commands into Marimo notebooks. When victims open crafted notebooks in edit mode, arbitrary code executes as local subprocesses, enabling privilege escalation and lateral movement into connected cloud workloads. Runtime segmentation helps contain post-compromise activity across development environments. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/marimo-notebook-mcp-code-injection-cve-2026-75149

    Post summary

    Threat researchers report that attackers are actively exploiting CVE‑2026‑75149 by injecting malicious MCP commands into Marimo notebooks, enabling arbitrary code execution, privilege escalation, and lateral movement in cloud workloads.

    0000062
    1.9K followersView on X
  • Mitch (Casspari)@mitchcasspari
    General

    Marimo schließt MCP-Code-Injection: CVE-2026-75149 im Edit-Modus: https://ift.tt/BIPmx9O - #hacker #news #technology #technologie #it #informationstechnologie #hacking #computer #nerds #itsicherheit #itsecurity #itnews #cybercrime #cybersecurity #hacks

    Post summary

    Marimo reported the closure of an MCP code injection vulnerability (CVE‑2026‑75149) in edit mode, linking to further details, but no PoC, exploit, or patch information is provided in the tweet.

    0000052
    614 followersView on X

Explore more