Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39987-marimo-rce — CVE-2026-39987 | Kitploit
Tools/GitHubGitHub/0xdeadroot/cve-2026-39987-marimo-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRemote Access Tool
GitHub0xdeadroot/cve-2026-39987-marimo-rce

CVE-2026-39987-marimo-rce

CVE-2026-39987

View Repository
124 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-39987 - Marimo Pre-Auth RCE

Unauthenticated Remote Code Execution in Marimo via WebSocket Terminal

Critical Python Docker


📌 Overview

CVE-2026-39987 is a critical Pre-Authentication Remote Code Execution vulnerability affecting Marimo versions prior to 0.23.0. The /terminal/ws WebSocket endpoint completely bypasses authentication, allowing any unauthenticated attacker to obtain a full interactive PTY shell with the privileges of the Marimo process (typically root in Docker environments).


🛠️ Vulnerability Details

  • CVE ID: CVE-2026-39987
  • Affected Product: Marimo (Reactive Python Notebook)
  • Affected Versions: marimo < 0.23.0
  • Fixed Version: marimo >= 0.23.0
  • Attack Vector: Network (Unauthenticated)
  • Affected Endpoint: /terminal/ws
  • Impact: Full remote shell (PTY) as root

✨ PoC Features

  • Automatic http:// → ws:// and https:// → wss:// conversion
  • Intelligent PTY buffer draining
  • Reliable command execution
  • Clean, minimal and stable code
  • Ready for Docker lab testing

📁 Repository Structure

CVE-2026-39987/
├── CVE-2026-39987-poc.py          ← Main Exploit
├── docker-vulnerable/
│   ├── Dockerfile
│   └── docker-compose.yml
├── notebooks/                     ← Persistent notebooks (optional)
├── README.md
└── LICENSE

🚀 Usage

1. Install dependency

pip install websocket-client

2. Run the Exploit

# Basic usage
python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami && hostname"

# System enumeration
python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami && cat /etc/os-release && ls -la /app"

# Read sensitive files
python3 CVE-2026-39987-poc.py http://target:2718 "cat /etc/passwd && cat /root/.bash_history"

🧪 Vulnerable Docker Lab

cd docker-vulnerable
docker compose up --build -d

Then test:

python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami"

🛡️ Mitigation

  • Upgrade immediately to marimo >= 0.23.0
  • Do not expose Marimo directly to the internet
  • Place behind a reverse proxy with authentication
  • Run as non-root user whenever possible
  • Restrict access to /terminal/ws via firewall or proxy rules

⚠️ Disclaimer

This Proof of Concept is intended for educational purposes and authorized security testing only. The author is not responsible for any misuse or damage caused by this tool. Ensure you have explicit permission before testing any system.

Use ethically and responsibly.


📄 References

  • Official CVE Advisory
  • Marimo GitHub Repository
  • NVD Entry (CVE-2026-39987)

Made for security research & responsible disclosure.

Download Tool