What is CVE-2026-67618?
A configuration injection vulnerability in marimo versions before 0.23.15 allows notebook authors to exfiltrate operator API keys. Attackers can embed a malicious base_url in PEP-723 inline script metadata, which overrides the operator's settings with higher precedence. Users should immediately upgrade to marimo 0.23.15 or later.
Azərbaycanca: marimo 0.23.15-dən əvvəlki versiyalarda aşkar edilmiş bu boşluq notebook müəlliflərinə operatorun API açarlarını oğurlamağa imkan verir. Təcavüzkar PEP-723 metadata daxilində zərərli `base_url` təyin edərək sessiya konfiqurasiyasını manipulyasiya edə bilər. İstifadəçilər dərhal marimo-nu 0.23.15 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What software is affected by CVE-2026-67618 and how does the attack occur?
This vulnerability affects marimo versions before 0.23.15. Attackers can embed a malicious base_url in PEP-723 inline script metadata, overriding the operator's session configuration to exfiltrate API keys.
What should I do to protect against CVE-2026-67618?
Users should immediately upgrade to marimo 0.23.15 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.