AI Weekly Malaysia

Back to items Summaries

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

ID
24644
Status
summarized
Published
15 Sep 2026, 7:52 PM
Fetched
15 Sep 2026, 9:26 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
15 Sep 2026, 9:27 PM
Tags
Audience
developersai_ml_learnersvibe_coders

What happened

Sysdig reports a skilled human attacker exploited CVE-2026-39987 (CVSS 9.3), a pre-auth RCE in all versions of Marimo notebooks, to pivot from a vulnerable Marimo instance to an SSH bastion host in eight seconds. The attacker hand-wrote a custom Python toolkit (no AI agent), harvested AWS credentials from the compromised instance, called AWS Secrets Manager, and used the retrieved private key for SSH access—all within a nine-hour session issuing 850+ interactive commands.

Why it matters

If you run Marimo notebooks in any environment, patch or restrict access immediately—this CVE is pre-auth and affects all versions, with active exploitation within hours of disclosure. The eight-second credential-to-SSH pivot means there is no manual response window; any exposed Marimo terminal WebSocket endpoint is effectively a direct path to your cloud secrets.

Discussion angle

The article contrasts this human operator against AI-assisted threat actors who fell into a trap the human skipped—worth discussing whether agentic security tooling is actually catching up to skilled humans, or if the gap is widening in the other direction.

Top