CuraSec

tag: Notebook-Vulnerability · 1 items

  • Engineer — Plan: Teams using Marimo in AI/ML workflows should update to the patched version; the attack surface (opening a crafted notebook in edit mode triggers a local subprocess via MCP) is a real supply-chain-style risk, but no KEV listing, public PoC, or active exploitation signals mean this isn’t an emergency patch.
  • SOC/IR — Skip
  • Leader — Skip