15-09-2026
Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit
https://www.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit
Report completeness: Low
Actors/Campaigns:
Scarleteel
Threats:
Nkabuse
Revshell_tool
Victims:
Marimo notebook hosts, Aws accounts, Bastion hosts
CVEs:
CVE-2026-39987 [Vulners]
CVSS V3.1: 9.8,
Vulners: Exploitation: True
Soft:
- coreweave marimo (<0.23.0)
ChatGPT TTPs:
do not use without manual checkT1005, T1021.004, T1027, T1033, T1049, T1059.004, T1059.006, T1078.004, T1082, T1140, have more...
IOCs:
IP: 2
File: 16
Domain: 0
Url: 0
Hash: 0
Email: 0
BrowserExtension: 0
Soft:
Redis, boto3, GuardDuty
Algorithms:
base64
Functions:
Manager, GetCallerIdentity, AWS, validate_auth, SendSSHPublicKey
Win API:
Ed25519Key, SSHClient
Languages:
python
Links:
https://github.com/marimo-team/marimo/pull/9098