Skip to main content
CyberConfirmedMediumDeveloping
7.0

Marimo notebook vulnerability CVE-2026-75149 allows unauthorized MCP command execution

A critical vulnerability in Marimo notebooks allows for the execution of Model Context Protocol (MCP) commands upon opening a crafted file in edit mode. The flaw, tracked as CVE-2026-75149, has been patched in version 0.23.15, necessitating immediate updates for users of earlier versions to prevent potential arbitrary code execution.

The Hacker Newsabout 8 hours agoengCredibility 59%View source

Score Breakdown

Mosaic Score7.0
Confidence0.9
Significance0.5
Source credibility0.6
Source

Related signals

8 found