{"id":"CVE-2026-67618","published":"2026-08-04T15:16:41.293","lastModified":"2026-08-04T16:16:27.920","description":"marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","cwes":["CWE-345"],"vendors":[],"products":[],"references":[{"url":"https://github.com/marimo-team/marimo/commit/1a21bd71e258438d2511136b5edacc94c08855f4","tags":[]},{"url":"https://github.com/marimo-team/marimo/pull/10281","tags":[]},{"url":"https://github.com/marimo-team/marimo/releases/tag/0.23.15","tags":[]},{"url":"https://www.vulncheck.com/advisories/marimo-api-key-exfiltration-via-malicious-notebook-pep-723-metadata","tags":[]}],"exploitRefs":[{"url":"https://github.com/marimo-team/marimo/commit/1a21bd71e258438d2511136b5edacc94c08855f4","tags":[]},{"url":"https://github.com/marimo-team/marimo/pull/10281","tags":[]},{"url":"https://github.com/marimo-team/marimo/releases/tag/0.23.15","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows notebook authors to inject a malicious base_url that exfiltrates operator API keys, compromising security.","exploitability":"Exploitation requires embedding a specific script in a crafted notebook and having an operator open it; moderate technical skill is needed.","blast_radius":"If exploited, this could lead to unauthorized access to sensitive API keys across multiple operators' environments.","remediation":"Update marimo to version 0.23.15 or later to mitigate the vulnerability.","tags":["api-key-exfiltration","configuration-injection","security-vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:05:41.916Z"}}