Marimo Security Update Advisory (CVE-2026-39987)
Overview. an authentication bypass remote code execution vulnerability (CVE-2026-39987) has been reported in marimo. the vulnerability is a pre-authentication (Pre-Auth) vulnerability that allows remote code execution without authorization via bypassing Terminal WebSocket authentication. Affected versions and scope. affected versions are reported to be marimo 0.20.4 and earlier. systems and services

