Rahmi Demir ⭐⭐⭐⭐⭐[verified]@rahmid3mirPatch
CVE‑2026‑75149 in the Marimo notebook platform allows arbitrary MCP command execution via a malicious notebook; CVSS 3.1 8.8. The recommended mitigation is updating to Marimo 0.23.15+, which restricts untrusted notebook metadata and configuration fields.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
Threat researchers report that attackers are actively exploiting CVE‑2026‑75149 by injecting malicious MCP commands into Marimo notebooks, enabling arbitrary code execution, privilege escalation, and lateral movement in cloud workloads.
The Hacker News@TheHackersNewsPatch
Marimo CVE-2026-75149 lets crafted notebooks launch MCP commands pre-cell execution; patch available in 0.23.15; no evidence of active exploitation or PoC.
كاسبر سكاي@KasperskyDevPatch
CVE-2026-75149 is a high‑severity code injection flaw in Marimo versions below 0.23.15 that permits unauthenticated execution of malicious commands; users should upgrade to v0.23.15.
Swif@swif_aiPatch
Marimo has released a patch for CVE-2026-75149, a zero‑authentication RCE caused by malicious notebook configurations that run attacker‑set MCP commands before execution. The advisory provides the CVSS score and remediation guidance.
Mitch (Casspari)@mitchcasspariGeneral
Marimo reported the closure of an MCP code injection vulnerability (CVE‑2026‑75149) in edit mode, linking to further details, but no PoC, exploit, or patch information is provided in the tweet.