Likely 0-day
The /mpl/<port>/<route> endpoint, which is accessible without authentication on default Marimo installations allows for external attackers to reach internal services and arbitrary ports.
id: marimo-proxy-abuse
info:
name: Marimo > 0.9.20 - Proxy Abuse
author: ritikchaddha
severit
...