Ethical Hacking News
Marimo Notebook software users are advised to upgrade to version 0.23.15 or later to address a critical security flaw that could allow an attacker to execute an attacker-supplied Model Context Protocol (MCP) command before any notebook cell is executed in edit mode.
Vulnerability discovered in Marimo Notebook software with a high CVSS score of 8.7/8.8. Vulnerability affects versions prior to 0.23.15, allowing code injection and arbitrary command execution. Patch released in version 0.23.15, treating notebook metadata as attacker-controlled. Another vulnerability, CVE-2026-67618, discovered with similar impact. Users urged to upgrade to version 0.23.15 or later and be cautious when using the software.
A recent vulnerability in the Marimo Notebook software has brought to light a critical security flaw that could allow an attacker to execute an attacker-supplied Model Context Protocol (MCP) command before any notebook cell is executed in edit mode. This alarming discovery was made by VulnCheck's CVE Numbering Authority (CNA) record, which assigns a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8 to the vulnerability, indicating a high level of severity.
According to the CNA record, the vulnerability, tracked as CVE-2026-75149, affects versions prior to 0.23.15 of the Marimo Notebook software. The vulnerability is a code injection issue that can run as a local subprocess when the notebook is opened in edit mode. This means that an attacker could potentially execute arbitrary commands on the system, compromising the security of the notebook and the data it contains.
The vulnerability was discovered by Gregory Tan, who uses the handle Grg0rry, and was addressed by Marimo in version 0.23.15. The patch treats notebook metadata as attacker-controlled and passes notebook-supplied configuration through an allowlist, removing certain sections of notebook-supplied configuration that could be used to exploit the vulnerability.
Furthermore, the vulnerability is not an isolated incident, as another vulnerability, CVE-2026-67618, was discovered by VulnCheck on August 4, 2026, which affects Marimo versions before 0.23.15 and involves an attacker-controlled artificial intelligence (AI) base_url supplied through notebook metadata. This vulnerability could allow an attacker to supply an attacker-controlled AI base_url, which could be used to compromise the security of the notebook and the data it contains.
It's worth noting that Marimo's security policy states that security patches are provided for the latest stable release, and the company encourages users to stay current with the latest updates to prevent exploitation of known vulnerabilities.
In light of this discovery, it's essential for users of Marimo Notebook software to take immediate action to protect themselves against this vulnerability. This includes upgrading to version 0.23.15 or later, which addresses the CVE-2026-75149 vulnerability, and being cautious when using the software, especially in edit mode.
The discovery of this vulnerability highlights the importance of regular security updates and the need for users to stay informed about known vulnerabilities in their software. By staying up-to-date with the latest security patches and being vigilant about potential security risks, users can help prevent exploitation of vulnerabilities like CVE-2026-75149.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Marimo-Notebook-Flaw-A-Code-Injection-Conundrum-with-High-Severity-Consequences-ehn.shtml
https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
https://nvd.nist.gov/vuln/detail/CVE-2026-75149
https://www.cvedetails.com/cve/CVE-2026-75149/
https://nvd.nist.gov/vuln/detail/CVE-2026-67618
https://www.cvedetails.com/cve/CVE-2026-67618/
Published: Tue Aug 25 11:04:43 2026 by llama3.2 3B Q4_K_M