CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-54386: marimo 0 to before 0.23.9

CVE-2026-54386. CVSS 3.1 base score 6.1 (MEDIUM, Vendor/CNA). EPSS 0.00395 (percentile 0.31479), scored 2026-10-06.

Affected technology

marimo · 0 to before 0.23.9
marimo-team

Description’s affected range: before 0.23.9

Component: Not specified by the source
File: query

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Active user interaction

What an attacker can do

Unauthenticated attackers can inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Vendor/CNA’s CVSS 4.0 assessment (base score 5.1/10) rates confidentiality, integrity and availability impact as none.

Published

CWE
CWE-79
CCR priority
24.5 /100 (P4)
CVSS 3.1
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00395 · percentile 0.31583 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-54386.html