CVE-2026-54386
Last modified
CVE-2026-54386 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a malicious link with a payload beginning with __new__ to bypass the 404 check and inject JavaScript into the page, which executes without Content-Security-Policy restrictions in the origin of a victim's marimo server.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenticated attackers to inject arbitrary JavaScript by exploiting improper escaping of single quotes in the file query parameter reflected into an inline JavaScript string literal. Attackers can craft a malicious link with a payload beginning with __new__ to bypass the 404 check and inject JavaScript into the page, which executes without Content-Security-Policy restrictions in the origin of a victim's marimo server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54386?
How severe is CVE-2026-54386?
How do I fix CVE-2026-54386?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54368CentreStack before 17.4 contains a SQL injection vulnerabili…8.8
- CVE-2026-54369acl before version 2.4.0 contains a symlink traversal vulner…8.4
- CVE-2026-5437An out-of-bounds read vulnerability exists in `DicomStreamRe…7.5
- CVE-2026-54370acl before version 2.4.0 contains a time-of-check to time-of…7.2
- CVE-2026-54371attr before version 2.6.0 contains a symlink traversal vulne…8.4
- CVE-2026-5438A gzip decompression bomb vulnerability exists when Orthanc …7.5
- CVE-2026-54387Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to …9.3
- CVE-2026-54388Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to …9.3
- CVE-2026-5439A memory exhaustion vulnerability exists in ZIP archive proc…7.5
- CVE-2026-54390JTL Shop versions 5.2.0 through 5.7.1 contains a server-side…9.8
- CVE-2026-54393A stored cross-site scripting vulnerability exists in MISP w…5.1
- CVE-2026-54394MISP contains a path traversal vulnerability in Organisation…5.3
Are you affected by CVE-2026-54386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
