Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
A human attacker exploited a critical vulnerability in the Marimo notebook platform to gain authenticated access on an SSH bastion host in eight seconds, according to Sysdig’s Threat Research Team. The attack, which targeted CVE-2026-39987, involved chaining initial shell access, cloud credential use and retrieval of an SSH private key.
The attacker used a hand-built Python toolkit rather than an AI agent, demonstrating manual debugging, varied command construction and deliberate pacing. The operator issued over 850 interactive commands over a nine-hour session, writing, testing and refining scripts manually before reusing them to accelerate later access attempts.
The attack began when a new WebSocket session was opened, and successful authentication to the bastion host followed shortly after. The operator obtained AWS credentials from the compromised environment and Redis backend, mapping to different IAM users. The vulnerability, which stems from missing authentication checks on Marimo’s WebSocket endpoint, was disclosed on April 8 and rated critical.
Marimo advised users to upgrade to version 0.23.0, which added the necessary authentication validation.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Human operator executes Marimo cloud pivot in eight seconds thearabianpost.com