HIGHVulnerability
Verified
Global

CISA KEV: Marimo Marimo — Marimo Remote Code Execution Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Analysis

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-23. Remediation due: 2026-05-07.

Indicators of Compromise (1)

CVE (1)
CVE-2026-39987
Source Attribution

Originally published by CISA KEV on Apr 23, 2026. Verified by: CISA.

Related Threats