Human attacker hits machine-speed exploitation of Marimo RCE, pivots in 8 seconds

ChuckDBrooks · x · 2026-09-15

Sysdig's Threat Research Team detailed how a human attacker exploited CVE-2026-39987, a pre-auth RCE in Marimo notebooks (fixed in 0.23.0), pivoting from the vulnerable notebook to an SSH bastion in 8 seconds — a speed usually associated with AI-driven attacks, with no sign of LLM use. The flaw lives in Marimo's terminal WebSocket endpoint, which skipped authentication. The attacker harvested cloud credentials from the process environment and Redis backend, pulled an SSH key from AWS Secrets Manager, and reached the bastion. The 8-second chain was pre-built: the operator spent 4 hours developing and staging 8 Python scripts on the host before reconnecting. Marimo notebooks often run alongside ML pipelines with GPU access and cloud/model-provider credentials, making them a gateway to victims' cloud accounts.

Original post →

More from Infra

Infra channel →