
Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds
A threat actor exploited a pre-authentication remote code execution flaw in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in eight seconds. Tracked as CVE-2026-39987, the vulnerability affects marimo versions through 0.20.4. The flaw stems from missing authentication on /terminal/ws, exposing an interactive […]
The post Marimo RCE Flaw Lets Hackers Steal AWS Credentials and Pivot to Bastion Host in 8 Seconds appeared first on Cyber Security News.