marimo is vulnerable to Exposure of Sensitive Information
65
Medium Risk
marimo merges configuration taken from a notebook's PEP-723 inline script metadata into the running session with higher precedence than the operator's own settings. The pyproject sanitizer does not sufficiently restrict which fields a notebook may set, so a notebook author can inject a custom AI base URL. When the operator opens the crafted notebook and makes an AI request, marimo sends the request to the notebook-controlled endpoint while authenticating with the operator's configured API key, leaking that key without any cell execution. The fix tightens sanitization so untrusted notebook metadata can no longer override sensitive connection settings.
You are affected if you are using a version that falls within the vulnerable range and you open an untrusted notebook containing PEP-723 script metadata and then make an AI request while an operator API key such as OPENAI_API_KEY is configured.
marimo is vulnerable to Exposure of Sensitive Information in versions 0.11.5 - 0.23.14.
Upgrade the marimo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant