Vito Botta’s Post

Marimo, an open-source Python notebook for data science, had an RCE flaw exploited within 10 hours of disclosure. No PoC existed, attackers built their exploit directly from the advisory description. The vulnerability was an unauthenticated WebSocket endpoint that gave full shell access. Data science tools running in production are becoming primary targets, and the time to exploit window keeps shrinking. Patch immediately if you're using Marimo.

To view or add a comment, sign in

Explore content categories