Tartışma

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Başlatan The Hacker News · 25 Ağu 2026 17:14 · 12 Görüntülenme · 0 Yanıtlar
Konuyu Açan #0
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record.

The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.

The vulnerability, tracked

Okumaya devam et...

Yanıt vermek için giriş yapmış olmalısınız.

0 alıntı seçildi