EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Marimo's notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, affecting releases prior to the patched release and presenting a high risk of code injection. The issue can be exploited when the notebook is opened in edit mode, allowing an attacker to run a local subprocess with user interaction required and no attacker authentication needed. These vulnerabilities collectively present a significant risk for users running affected releases, who should move to a release outside the affected range.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple vulnerabilities have been identified in Marimo's notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, affecting releases prior to the patched release and presenting a high risk of code injection. The issue can be exploited when the notebook is opened in edit mode, allowing an attacker to run a local subprocess with user interaction required and no attacker authentication needed. These vulnerabilities collectively present a significant risk for users running affected releases, who should move to a release outside the affected range.[emaillocker id="1283"]
CVE-2026-75149 (CVSS 8.7 — High): A code injection issue affecting Marimo Notebook, where an attacker can supply an attacker-controlled MCP server command through notebook configuration when the victim opens the notebook in edit mode.
CVE-2026-67618 (CVSS 7.1 — High): An attacker-controlled artificial intelligence base_url supplied through notebook metadata affects Marimo Notebook, allowing an operator to receive the operator's API key without requiring a notebook cell to be executed when making an AI request.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html