
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
A high-severity security flaw in Marimo's notebook software allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook. The vulnerability, tracked as CVE-2026-75149, affects versions prior to 0.23.15 and has be…




