marimo vulnerabilities
CVEs whose affected-version data names the marimo package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54386Medium· 6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
marimo contains a reflected cross-site scripting vulnerability in the notebook page
▾ Sunlitmarimo · marimoEPSS 0.40%via GHSA
GHSA-xjv7-6w92-42r7Mediummarimo vulnerable to proxy abuse of /mpl/{port}/
marimo vulnerable to proxy abuse of /mpl/{port}/
▾ Sunlitmarimo · marimovia OSV