Marimo Patches CVE-2026-75149, an 8.7-Severity Code-Injection Flaw Triggered by a Notebook's MCP Configuration
A crafted marimo notebook could run an attacker's command as a local subprocess the moment it was opened in edit mode, via a fake MCP server entry in its configuration.