Critical Security Flaw in Marimo Notebook Allows Pre-Execution MCP Command Injection
A critical security flaw (CVE-2026-75149) in Marimo Notebook allows execution of attacker-supplied Model Context Protocol (MCP) commands before notebook cells run in edit mode, with a patch released in version 0.23.15. The vulnerability requires user interaction and affects versions prior to 0.23.15, posing risks for unauthorized command execution.
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record.
The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.
The vulnerability, tracked
*** END OF TRANSMISSION ***