System running
Last check: 2026-09-29 01:26:15 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-39987

Severity
CRITICAL
CVSS Score
9.8
Description

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipp...

PoCs for CVE-CVE-2026-39987

CVE-2026-39987
RCE Python 0
K3ysTr0K3R 2026-08-19
CVE-2026-39987.py
General Python 0
dodeepsink 2026-08-20
CVE-2026-39987-PoC
General Python 0
stapat1245 2026-09-07
CVE-2026-39987_POC
RCE Python 0
julichaan 2026-09-11
CVE-2026-39987_RCE_PoC
RCE Python 0
mfahdk 2026-09-20
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources