Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
The Hacker News
Read full postMarimo fixed a critical security flaw (CVE-2026-75149) in its notebook software that allowed execution of attacker-supplied MCP commands as local subprocesses before notebook cells run. The vulnerability affected versions before 0.23.15 and required user interaction but no authentication. Users are urged to update to version 0.23.15 or later to mitigate the risk.



