Marimo Patches Notebook Flaw That Let Hidden Commands Run on Open

A high-severity bug in the Marimo notebook app could quietly run attacker-supplied commands the moment a user opened a booby-trapped file in edit mode.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: A developer's workspace with a Jupyter-
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Marimo, a Python notebook application, patched a high-severity flaw that let a rigged notebook run a hidden command on the user's computer the moment the file was opened in edit mode.
  • The bug abuses the Model Context Protocol (MCP), a standard way for AI tools to talk to outside programs, to launch a local subprocess without the user running any code cell.
  • VulnCheck, acting as the official CVE Numbering Authority for the bug, published the advisory describing the issue.
  • Update Marimo immediately and don't open notebooks from untrusted sources until you have.

Marimo has fixed a flaw in its notebook software that could hand an attacker code execution on a user's machine the moment a malicious file was opened.

The vulnerability sits in how Marimo handles the Model Context Protocol, or MCP, a standard that lets AI assistants and developer tools call outside programs in a structured way. An attacker could embed an MCP command inside a notebook file. Open that file in edit mode and the command runs as a local subprocess. No cell needs executing, and nothing warns you.

That matters because notebooks travel like documents. Researchers pass them around, students download them, data teams pull them from public repositories. A file that looks like a harmless analysis could quietly launch a program the moment it loads. It's the same threat model as a malicious Office macro, only the victim pool is technical and therefore trusted with more sensitive systems.

What is Marimo, and who uses it?

Marimo is an open-source Python notebook competing with the widely used Jupyter. Its users are mostly analysts, machine learning engineers and academics who mix code, charts and explanatory text in a single shareable file.

The practical risk is identical to any document-borne attack: trick someone into opening the file and you win. The attacker doesn't need a second step.

How serious is the bug?

VulnCheck, acting here as the CVE Numbering Authority (an organisation authorised to assign official tracking IDs to vulnerabilities), rated it high severity. According to VulnCheck's CNA record, the command runs as a local subprocess when the notebook is opened in edit mode. That's Marimo's default working view, not an obscure configuration.

A subprocess is a separate program launched by the app. It runs with the same permissions as the person who opened the file. For a developer with access to source code, cloud credentials or internal systems, that reach transfers to the attacker immediately. We covered a similar unauthenticated command-execution issue in JetBrains TeamCity on 28 July 2026, where the blast radius was also defined by the victim's own access level.

Detail Value
Affected product Marimo notebook
Vulnerability type Command execution via MCP
Trigger Opening a crafted notebook in edit mode
Severity High
CNA of record VulnCheck

What should users do now?

Update Marimo to the patched release. After that, treat any notebook from an unknown sender the way you'd treat an unexpected email attachment: if you can't verify the source, don't open it in edit mode.

Teams sharing notebooks internally should audit where their files originate. Forum downloads and unsolicited shares carry the highest risk. Running Marimo inside a container or a throwaway virtual machine limits the damage if a bad file slips through.

Should you worry about MCP more broadly?

Yes, and this won't be the last advisory like it. As more tools wire AI assistants into local systems through MCP, the attack surface for silent-execution bugs grows. The protocol is young, adoption is moving faster than security review, and the default gating on MCP calls varies widely between implementations. Vendors who haven't asked themselves what an attacker can do with a crafted MCP payload before a user clicks anything should be asking now.

© 2026 Threat Vectr