
Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.
This project focuses on CVE-2026-39987, a pre-authentication Remote Code Execution vulnerability in Marimo related to the terminal WebSocket endpoint /terminal/ws.
Marimo is an open-source reactive Python notebook that allows users to write and execute Python code through a web interface. Because notebook platforms can execute code on the server side, privileged features such as terminal access must be protected by proper authentication and access control.
In vulnerable Marimo versions, authentication was not properly enforced on the terminal WebSocket endpoint. As a result, an unauthenticated user could potentially access terminal functionality and execute commands in the environment where Marimo is running.
The goal of this project is to reproduce the vulnerability in a local Docker lab, analyze the root cause, compare the vulnerable and patched versions, and verify that the fix prevents the issue.
/terminal/ws/terminal/wsThis project is for educational purposes only. All testing will be performed in a local Docker lab environment.