Sploitus

CVE-2026-39987

17 known exploits for CVE-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

Affected products
Marimo
Coreweave Marimo
< 0.23.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
96.6% (100th percentile)
Weakness
CWE-306
NVD status
Analyzed
Published
2026-04-09
CVE-2026-39987 at NVD
Authoritative description, scoring and affected products

17 known exploits for CVE-2026-39987

Proof-of-concept code and exploit modules indexed by Sploitus

cve-analysis-lab
2026-08-14 harshal561GITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-12 matesz44GITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-10 MADA0LGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-07 alreadyClosedGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-02 gbuyssensGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-02 jasonbernierGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-08-02 vanhariGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-06-02 jenniferreire26GITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-05-16 0xdeadrootGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-05-04 rootdirective-secGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-05-04 rootdirective-secGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-04-26 Dhiaelhak-RachedGITHUB
Exploit for Missing Authentication for Critical Function in Coreweave Marimo
2026-04-25 h3raklezGITHUB
Exploit for CVE-2026-39987
2026-04-18 NxploitedGITHUB
Exploit for CVE-2026-39987
2026-04-15 keraattinGITHUB
Exploit for CVE-2026-39987
2026-04-13 fevar54GITHUB
Exploit for CVE-2026-39987
2026-04-13 mki9GITHUB