← Back to feed
AI SecurityEmerging1 sourceAug 19, 2026 · 18:17via CVEFeed

CVE-2026-75149 - marimo 0.23.15 Code Injection via MCP Server Configuration

Brief

CVE ID : CVE-2026-75149

Published : Aug. 19, 2026, 6:17 p. m.

  • 51 minutes ago

Description : marimo before 0.

  • 15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook.

When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.

Severity: 8.8

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed