GITHUBEXPLOIT 9.8 CRITICAL

Exploit for Missing Authentication for Critical Function in Coreweave Marimo_3FB6634C-D5B2-5558-836C-394AF35624C1

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

CVE-2026-39987 — Marimo Pre-Auth RCE For educational and authorized security research purposes only. Description Pre-authenticated Remote Code Execution in Marimo = 0.20.4. The WebSocket endpoint /terminal/ws skips authentication validation, allowing...
Visit Original Source

Basic Information

ID 3FB6634C-D5B2-5558-836C-394AF35624C1
Published Apr 25, 2026 at 16:50
Modified Apr 25, 2026 at 16:53

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.