marimo is vulnerable to Code Injection
59
Medium Risk
marimo can resolve OpenGraph preview metadata for notebooks by executing a notebook-defined generator function referenced in PEP-723 script metadata. The server runs this generator automatically while resolving previews for index, file-listing, and thumbnail requests, so merely serving or listing a notebook executes its code without the notebook being run. A server that hosts or lists untrusted notebooks therefore runs arbitrary Python supplied by the notebook author. The fix makes generator execution opt-in behind an explicit flag that defaults to off.
You are affected if you are using a version that falls within the vulnerable range and you serve or list untrusted notebooks that declare an OpenGraph generator, for example through a gallery or multi-notebook server.
marimo is vulnerable to Code Injection in versions 0.19.8 - 0.23.14.
Upgrade the marimo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant