Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-39987-Marimo-Preauth-RCE — Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab. | Kitploit
Tools/GitHubGitHub/laarana12/cve-2026-39987-marimo-preauth-rce
Container SecurityVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRemote Access ToolLabs & Practice

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHub
laarana12/cve-2026-39987-marimo-preauth-rce

CVE-2026-39987-Marimo-Preauth-RCE

Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.

View Repository
111 day agoNot yet reviewed

CVE-2026-39987 Marimo Pre-auth RCE Research

Overview

  • This project focuses on CVE-2026-39987, a pre-authentication Remote Code Execution vulnerability in Marimo related to the terminal WebSocket endpoint /terminal/ws.

  • Marimo is an open-source reactive Python notebook that allows users to write and execute Python code through a web interface. Because notebook platforms can execute code on the server side, privileged features such as terminal access must be protected by proper authentication and access control.

  • In vulnerable Marimo versions, authentication was not properly enforced on the terminal WebSocket endpoint. As a result, an unauthenticated user could potentially access terminal functionality and execute commands in the environment where Marimo is running.

  • The goal of this project is to reproduce the vulnerability in a local Docker lab, analyze the root cause, compare the vulnerable and patched versions, and verify that the fix prevents the issue.

CVE Information

  • CVE ID: CVE-2026-39987
  • Product: Marimo
  • Vulnerability type: Missing Authentication for Critical Function
  • CWE: CWE-306
  • Affected versions: Marimo < 0.23.0
  • Fixed version: Marimo 0.23.0+
  • Affected endpoint: /terminal/ws
  • Impact: Pre-authenticated Remote Code Execution
  • Severity: Critical
  • CVSS v4.0: 9.3
  • CVSS v3.1: 9.8

Project Goals

  • Understand Marimo and the vulnerability context
  • Build a vulnerable local Docker lab
  • Reproduce the vulnerability safely in localhost
  • Analyze the root cause in /terminal/ws
  • Perform patch diffing between vulnerable and fixed versions
  • Verify the fix on patched Marimo
  • Write mitigation and lessons learned

Lab Environments

  • OS: Windows 11
  • Docker version: 29.0.0
  • Docker Compose version: v5.5.1
  • Python version: 3.11.9
  • Vulnerable Marimo version: TODO
  • Patched Marimo version: TODO

Project Status

  • Research CVE
  • Build vulnerable lab
  • Build patched lab
  • Reproduce PoC
  • Root cause analysis
  • Patch diff
  • Verify fix
  • Final report

Disclaimer

This project is for educational purposes only. All testing will be performed in a local Docker lab environment.

Download Tool