SECURITY·중요도 8·2026. 08. 25.·The Hacker News
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
── KO ──────────────────
Marimo 노트북 소프트웨어의 보안 취약점이 수정되었습니다.
Marimo는 노트북 소프트웨어의 심각한 보안 취약점을 해결했습니다. 이 취약점은 공격자가 특별히 제작된 노트북에서 모델 컨텍스트 프로토콜(MCP) 명령을 실행할 수 있게 했습니다. 공격자는 노트북이 편집 모드에서 열릴 때, 로컬 서브프로세스로 명령을 실행할 수 있었으며, 이 문제를 해결하기 위해 패치가 제공되었습니다.
── EN ──────────────────
Marimo has fixed a high-severity security flaw in its notebook software.
Marimo has addressed a serious security vulnerability in its notebook software that allowed attackers to execute Model Context Protocol (MCP) commands. This flaw permitted attackers to run commands as a local subprocess when the notebook was opened in edit mode. A patch has been released to fix this issue.