CVE-2026-75149 - marimo 0.23.15 Code Injection via MCP Server Configuration
Brief
CVE ID : CVE-2026-75149
Published : Aug. 19, 2026, 6:17 p. m.
- 51 minutes ago
Description : marimo before 0.
- 15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook.
When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.
Severity: 8.8
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
