OSV 1.4.0 · unreviewed · 修改于 2026-08-20 02:32
发布时间
2026-08-20 02:32
GitHub 审查时间
—
NVD 发布时间
2026-08-20 02:17
源文件
advisories/unreviewed/2026/08/GHSA-gfgh-xp6v-q37q/GHSA-gfgh-xp6v-q37q.json
marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. When the notebook is opened in edit mode, marimo launches the specified command as a local subprocess before any notebook cell is executed, requiring no authentication or cell execution to trigger the vulnerability.
该公告没有提供结构化的受影响软件包信息。