All verified exploits

CVE-2026-39987 Unauthenticated Terminal Access via WebSocket Auth Bypass

Deterministic critical marimo Added cve-verified-cve-2026-39987

Detects marimo notebook instances before version 0.23.0 where the /terminal/ws WebSocket endpoint does not call validate_auth(). An unauthenticated attacker connects and receives a full PTY shell as the server process user, enabling arbitrary command execution. The fix adds authentication validation before accepting WebSocket connections.

Is your app exploitable through CVE-2026-39987?

Scan your domain free