在 marimo 版本 0.23.15 之前,笔记本配置处理器中存在代码注入漏洞。攻击者可以通过在笔记本中嵌入一个包含受控命令值的伪造 MCP 服务器条目,来执行任意命令。当笔记本以编辑模式打开时,marimo 会在执行任何笔记本单元格之前,将指定命令作为本地子进程启动。该漏洞无需认证或单元格执行即可触发。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| marimo-team | marimo | < 0.23.15 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| marimo-team | marimo | 0 ~ 0.23.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet