Marimo Patches CVE-2026-75149, an 8.7-Severity Code-Injection Flaw Triggered by a Notebook's MCP Configuration
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.
Editor's Note ·
- Correction:
- The article quotes NVD's CVE-2026-67618 description as saying the bug let "notebook authors exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata." NVD's actual text reads "...allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata..." — the word "to" was dropped from the quotation. The underlying claim is accurate; only the exact quoted wording was affected.
Overview
Marimo, an open-source Python notebook tool, has fixed a high-severity code-injection vulnerability that let a specially crafted notebook execute an attacker-controlled command as soon as it was opened in edit mode. The flaw, tracked as CVE-2026-75149, lived in the notebook configuration handler and was triggered through a fake Model Context Protocol (MCP) server entry embedded in a notebook’s metadata — no authentication and no cell execution required.
What We Know
According to the National Vulnerability Database entry for CVE-2026-75149, “marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.” The same description appears on marimo’s GitHub Security Advisory, which classifies the bug as CWE-94, Improper Control of Generation of Code.
NVD records two severity scores for the flaw: a CVSS v4.0 base score of 8.7 and a CVSS v3.1 base score of 8.8, both rated HIGH, with a network attack vector and low attack complexity, according to NVD. The CVE was published on August 19, 2026, per the same NVD record. The Hacker News reported that the CVE record credits Gregory Tan, who uses the GitHub handle Grg0rry, with discovering the flaw, and that the same handle appears as a co-author on marimo’s hardening commit.
The fix shipped in marimo 0.23.15, published on GitHub on July 23, 2026. The underlying fix commit, authored by marimo maintainer Dylan Madisetti and co-authored by Grg0rry under pull request #10281, adds an allowlist that restricts which top-level configuration sections a notebook’s own embedded metadata is permitted to set. A comment in the patched code explains the reasoning directly: notebook metadata following the PEP 723 inline-script-metadata format “is attacker-controllable and merged with the HIGHEST precedence over the operator’s own user config, so anything that affects outbound traffic or credentials must stay excluded,” naming “ai (base_url → credential exfiltration), mcp (url → outbound beacon), completion (api_key/base_url), secrets, server” as the sections notebook metadata can no longer touch, per the commit. Sections such as formatting, display, keymap, and package management remain configurable from notebook metadata, according to the same commit.
The same commit also closes a related, earlier-disclosed flaw in the same configuration-merging code path. NVD’s entry for CVE-2026-67618, published August 4, 2026, describes a configuration-injection bug that let “notebook authors exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata,” which was merged into session configuration “with higher precedence than the operator’s own settings.” When the operator made an AI request inside the crafted notebook, marimo would resolve the attacker’s base_url while still authenticating with the operator’s own API key, sending it to the attacker’s endpoint, per the same NVD record. NVD assigns that flaw a CVSS v4.0 score of 7.1. The Hacker News reported that both CVEs trace to the same underlying configuration boundary.
CVE-2026-75149 is unrelated to the pre-authentication remote-code-execution flaw in marimo’s /terminal/ws endpoint that The Machine Herald previously reported was weaponized within hours of its April 2026 disclosure. That flaw, tracked as CVE-2026-39987, involved a missing authentication check on a WebSocket endpoint and was fixed in marimo 0.23.0; the new flaw involves how notebook-supplied configuration is parsed and merged, and The Hacker News confirmed the two CVEs are separate.
What We Don’t Know
Neither NVD nor marimo’s GitHub advisory for CVE-2026-75149 discloses whether the flaw was exploited before it was patched, or how it was originally discovered beyond the researcher credit. The advisories do not state how widely marimo’s MCP integration is used in production notebook-sharing workflows, so the practical exposure window across the user base is not quantified in the available records.
Response and Remediation
Marimo’s fix, merged as part of pull request #10281, replaces notebook metadata’s ability to set arbitrary configuration sections with an explicit allowlist, so that any ai, mcp, completion, secrets, or server block embedded in a notebook’s own metadata is now dropped and logged as a security warning rather than applied, according to the commit. Users running marimo versions before 0.23.15 are affected and should upgrade, per NVD and marimo’s GitHub advisory.