[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feVCfD4zDPnHAl5zwOu6GqVofZirNxpuW5iGMYInOtd0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"33dff275-a693-4e96-b87a-7a5c6dd44c15","critical-pre-auth-rce-in-marimo-demands-emergency-patching","5257b43f-bb4a-4dce-bd2d-e1033d9137de","Critical Pre-Auth RCE in Marimo Demands Emergency Patching","CVE-2026-39987 demonstrates how a single vulnerability in a popular development framework can provide complete system compromise without any authentication requirements. The fact that attackers exploited this vulnerability within hours of disclosure highlights the critical importance of emergency patching procedures for internet-facing applications. With a CVSS score of 9.3 and the ability to gain full shell access through a simple WebSocket handshake, this vulnerability shows why development and notebook environments must be treated with the same security rigor as production systems. The rapid addition to CISA's KEV catalog underscores the severity and active threat landscape surrounding this vulnerability.","**Immediate actions:**\n- Upgrade all Marimo installations to version 0.23.0 or later immediately\n- Remove internet exposure for any Marimo instances that cannot be patched immediately\n- Conduct emergency scans to identify all Marimo deployments across the organization\n\n**Long-term improvements:**\n- Implement automated vulnerability scanning specifically for development frameworks and tools\n- Establish emergency patching procedures with defined timelines for critical vulnerabilities\n- Maintain comprehensive inventory of all development and notebook environments\n\n**Detection measures:**\n- Monitor WebSocket connections to Marimo instances for suspicious handshake patterns\n- Implement network segmentation to isolate development environments from production systems\n- Deploy endpoint detection on systems running notebook frameworks to identify unauthorized shell access",[12,13,14,15,16],"CIS Control 7.1","CIS Control 2.1","NIST SI-2","NIST CM-8","CISA KEV Catalog","published","2026-05-29T18:20:17.893542+00:00","2026-05-29T18:20:16.401+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fdarkwebinformer.com\u002Froot-in-one-request-pre-auth-rce-in-marimo-cve-2026-39987\u002F","root-in-one-request-pre-auth-rce-in-marimo-cve-2026-39987-9384f7","Root in One Request: Pre-Auth RCE in Marimo (CVE-2026-39987)",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[38,44],{"id":39,"date":40,"edition":41,"title":42,"audio_url":43},"6b82b89d-9f2a-4b5b-99d1-4da62d60cced","2026-05-31","afternoon","ThreatNoir Weekend Brief — May 31","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-31\u002Fthreatnoir-afternoon-brief-2026-05-31.mp3",{"id":45,"date":46,"edition":47,"title":48,"audio_url":49},"da871a1a-db6b-41fb-8f2c-6de86e645c2d","2026-05-30","morning","ThreatNoir Weekend Brief — May 30","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-05-30\u002Fthreatnoir-morning-brief-2026-05-30.mp3"]