CVE-2026-39987 | marimo-team marimo up to 0.22.x WebSocket Endpoint /terminal/ws validate_auth missing authentication
A vulnerability, which was classified as critical, has been found in marimo-team marimo up to 0.22.x. This vulnerability affects the function validate_auth of the file /terminal/ws of the component WebSocket Endpoint. This manipulation causes missing authentication.
This vulnerability appears as CVE-2026-39987. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.