VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_dd2b5b5f2275decff5b10d61b111ac2e

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Published Aug 25, 2026

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record.

The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.

The vulnerability, tracked

Affected AI Products

model context protocol
Get the weekly digest. Every Monday: top AI security stories of the week. Free.