Human operator executes Marimo cloud pivot in eight seconds
A skilled human attacker exploited a critical Marimo notebook flaw and moved from an exposed WebSocket session to authenticated access on an SSH bastion host in eight seconds, Sysdig’s Threat Research Team has documented. The operation centred on CVE-2026-39987, a pre-authentication remote code execution vulnerability affecting the Marimo Python notebook platform. Sysdig said the attacker used a…
A human attacker exploited a critical vulnerability in the Marimo notebook platform to gain authenticated access on an SSH bastion host in eight seconds, according to Sysdig’s Threat Research Team. The attack, which targeted CVE-2026-39987, involved chaining initial shell access, cloud credential use and retrieval of an SSH private key.
The attacker used a hand-built Python toolkit rather than an AI agent, demonstrating manual debugging, varied command construction and deliberate pacing. The operator issued over 850 interactive commands over a nine-hour session, writing, testing and refining scripts manually before reusing them to accelerate later access attempts.
The attack began when a new WebSocket session was opened, and successful authentication to the bastion host followed shortly after. The operator obtained AWS credentials from the compromised environment and Redis backend, mapping to different IAM users. The vulnerability, which stems from missing authentication checks on Marimo’s WebSocket endpoint, was disclosed on April 8 and rated critical.
Marimo advised users to upgrade to version 0.23.0, which added the necessary authentication validation.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.