Marimo RCE Steals AWS Keys in 8 Seconds
Hackers leveraged a critical vulnerability in the Marimo notebook platform, allowing them to steal AWS credentials and reach a bastion host in a mere eight seconds. This remote code execution flaw, identified as CVE-2026-39987, was exploited to breach systems running version 0.20.4 or earlier. Attackers targeted Marimo’s WebSocket endpoint, bypassing authentication to gain shell access. They quickly secured cloud credentials, utilizing them to query AWS Secrets Manager and retrieve an SSH private key. This key paved the way to access a bastion host, typically used to control entry into private cloud networks.
To mitigate such risks, it’s critical for organizations using the platform to upgrade to Marimo version 0.23.0 or later. Implementing strict IAM permissions and securing WebSocket services can prevent future intrusions. This incident underscores the rapid impact a compromised unauthenticated service can have on cloud environments. For a comprehensive understanding of how marimo RCE steals AWS credentials and additional protective measures, read the full article.
Hackers Exploit Marimo RCE to Steal AWS Credentials and Reach Bastion Host in 8 Seconds
