Veille cybersecurite : Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Source : The Hacker News
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck’s CVE Numbering Authority (CNA) record.
The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.
The vulnerability, tracked
Vous vous demandez si votre entreprise est exposee a ce type de faille ? Reservez un appel decouverte gratuit.