PT-2026-50557 · Marimo · Marimo

·

CVE-2026-54386

·

Published

2026-06-17

·

Updated

2026-07-13

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions marimo versions prior to 0.23.9
Description A reflected cross-site scripting issue exists in the notebook page. Unauthenticated attackers can inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter, which is reflected into an inline JavaScript string literal. By crafting a malicious link with a payload starting with new, attackers can bypass the 404 check and execute JavaScript within the origin of the victim's server, bypassing Content-Security-Policy restrictions.
Recommendations Update to version 0.23.9 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54386
GHSA-8M59-7XV8-735H
PYSEC-2026-2619

Affected Products

Marimo