Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has addressed a highseverity security flaw in its notebook software that allowed an attacker to execute an attackersupplied Model Context Protocol MCP command in a specially crafted notebook according to VulnChecks CVE Numbering Authority CNA record The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode The vulnerability tracked