{"id":2524,"date":"2026-08-25T16:10:52","date_gmt":"2026-08-25T16:10:52","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2524"},"modified":"2026-08-25T16:10:52","modified_gmt":"2026-08-25T16:10:52","slug":"marimo-notebook-flaw-could-run-mcp-commands-before-cells-execute-in-edit-mode","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2524","title":{"rendered":"Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Swati Khandelwal<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 25, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ AI Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgpC_dsMXsEscdzMT8fjZ3uZ86XgjBqYcYWA7ZodJJUvbK6vnmafx_dANiNsjoAeqYwDxzqeTerWaWEIMIZSmp7CqfynzhkfKEnuGIoizK5vihRhSJIeOVn4cK3CdIFjnURkvQvI1VX-Gm11mqNmxOQPVK5loEBRZ2ELFzLc1Y8C_z_ajrA5beUowEfwg0\/s1700-e365\/marimo.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck&#8217;s CVE Numbering Authority (CNA) record.<\/p>\n<p>The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-75149<\/strong>, is a code injection issue affecting versions prior to 0.23.15. VulnCheck&#8217;s CVE Numbering Authority (CNA) record assigns it a CVSS v4 score of 8.7 and a CVSS v3.1 score of 8.8, with user interaction required and no attacker authentication required.<\/p>\n<p>Marimo has addressed the issue in version 0.23.15. The CVE was published on August 19. Users running an affected release should move to a version outside the affected range.<\/p>\n<p>According to <a href=\"https:\/\/osv.dev\/vulnerability\/CVE-2026-75149\" target=\"_blank\">OSV&#8217;s CVE import<\/a>, a crafted notebook can supply an attacker-controlled MCP server command through notebook configuration.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The victim opens the notebook in edit mode. The CNA record says the specified command is launched as a local subprocess before any notebook cell is executed.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Marimo&#8217;s <a href=\"https:\/\/github.com\/marimo-team\/marimo\/commit\/1a21bd71e258438d2511136b5edacc94c08855f4\" target=\"_blank\">PEP 723 hardening patch<\/a> treats notebook metadata as attacker-controlled and passes notebook-supplied configuration through an allowlist.<\/p>\n<p>The following notebook-supplied configuration sections are removed &#8211;<\/p>\n<ul>\n<li>ai<\/li>\n<li>mcp<\/li>\n<li>completion<\/li>\n<li>secrets<\/li>\n<li>server<\/li>\n<\/ul>\n<p>The patch&#8217;s MCP regression case uses an attacker-controlled URL and verifies that the mcp section is removed. The CNA record supplies the separate command-to-subprocess behavior described for CVE-2026-75149.<\/p>\n<p>The Hacker News confirmed on August 25 that the <a href=\"https:\/\/pypi.org\/project\/marimo\/0.24.0\/\" target=\"_blank\">current PyPI release<\/a> is version 0.24.0, released August 17. Marimo&#8217;s <a href=\"https:\/\/github.com\/marimo-team\/marimo\/releases\/tag\/0.23.15\" target=\"_blank\">version 0.23.15 release<\/a> was published on July 23, 2026. Marimo&#8217;s <a href=\"https:\/\/github.com\/marimo-team\/marimo\/security\/policy\" target=\"_blank\">security policy<\/a> says security patches are provided for the latest stable release and encourages users to stay current.<\/p>\n<p>The CVE record credits Gregory Tan, who uses the handle Grg0rry, with discovering the flaw. The same handle also appears as a co-author on Marimo&#8217;s PEP 723 hardening commit.<\/p>\n<p>The same configuration boundary was addressed in VulnCheck&#8217;s <a href=\"https:\/\/www.vulncheck.com\/advisories\/marimo-api-key-exfiltration-via-malicious-notebook-pep-723-metadata\" target=\"_blank\">separate CVE-2026-67618 advisory<\/a> (CVSS score: 7.1), disclosed on August 4, 2026. That flaw affects Marimo versions before 0.23.15 and involves an attacker-controlled artificial intelligence (AI) base_url supplied through notebook metadata.<\/p>\n<p>For CVE-2026-67618, an operator opens the malicious notebook. The operator later makes an AI request. The configured endpoint then receives the operator&#8217;s API key without requiring a notebook cell to be executed.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>CVE-2026-75149 is separate from the earlier CVE-2026-39987 flaw in Marimo. <a href=\"https:\/\/github.com\/marimo-team\/marimo\/security\/advisories\/GHSA-2679-6mx9-h9xc\" target=\"_blank\">Marimo&#8217;s advisory<\/a> for that vulnerability states that versions 0.20.4 and earlier were affected by a missing authentication validation on the \/terminal\/ws endpoint.<\/p>\n<p>Requests reaching that endpoint could obtain a full pseudo-terminal (PTY) shell. The shell could then execute arbitrary commands. Marimo lists version 0.23.0 as the patched version for the earlier flaw.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Swati Khandelwal\ue802Aug 25, 2026Vulnerability \/ AI Security Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP)&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2525,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[968,195,3155,1832,70,1165,765,1944,3154,1774],"class_list":["post-2524","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-cells","tag-commands","tag-edit","tag-execute","tag-flaw","tag-marimo","tag-mcp","tag-mode","tag-notebook","tag-run"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2524","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2524"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2524\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2525"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2524"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2524"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2524"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}