VYPR
Vendor

Marimo Team

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-75149HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is…

  • CVE-2026-67618MedAug 4, 2026
    risk 0.35cvss 6.5epss 0.00

    marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the…

  • CVE-2026-54386MedJun 17, 2026
    risk 0.33cvss 6.1epss 0.00

    marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript…