Code Injection Vulnerability in Marimo Affected by Crafty MCP Server Configuration
CVE-2026-75149

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75149?

A code injection vulnerability exists in Marimo versions prior to 0.23.15, specifically within the notebook configuration handler. This issue enables attackers to execute arbitrary system commands by providing a specially crafted MCP server entry containing an attacker-controlled command value embedded within a notebook. When a victim opens the notebook in edit mode, the vulnerable Marimo client unwittingly launches the specified command as a local subprocess before executing any notebook cells. Notably, this exploit does not require any form of user authentication or prior execution of notebook cells, making it particularly insidious.

Affected Version(s)

marimo 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gregory Tan (Grg0rry)
.