Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8m59-7xv8-735h | marimo contains a reflected cross-site scripting vulnerability in the notebook page |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a malicious link with a payload beginning with __new__ to bypass the 404 check and inject JavaScript into the page, which executes without Content-Security-Policy restrictions in the origin of a victim's marimo server. | |
| Title | marimo < 0.23.9 XSS via file Query Parameter in assets.py | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-18T13:54:06.426Z
Reserved: 2026-06-12T20:20:02.950Z
Link: CVE-2026-54386
Updated: 2026-06-18T13:48:25.379Z
No data.
No data.
OpenCVE Enrichment
No data.
Github GHSA