Code Injection Vulnerability in Marimo Affected by Crafty MCP Server Configuration
CVE-2026-75149
What is CVE-2026-75149?
A code injection vulnerability exists in Marimo versions prior to 0.23.15, specifically within the notebook configuration handler. This issue enables attackers to execute arbitrary system commands by providing a specially crafted MCP server entry containing an attacker-controlled command value embedded within a notebook. When a victim opens the notebook in edit mode, the vulnerable Marimo client unwittingly launches the specified command as a local subprocess before executing any notebook cells. Notably, this exploit does not require any form of user authentication or prior execution of notebook cells, making it particularly insidious.
Affected Version(s)
marimo 0
News Articles
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo fixes CVE-2026-75149, an 8.7-severity flaw that can launch an MCP command before notebook cells run in edit mode.
3 weeks ago
References
CVSS V4
Timeline
- 📰
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved
