Threats Tagged 'cve-2026-67618'
View all threats tagged with 'cve-2026-67618'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-67618'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-67618: Insufficient Verification of Data Authenticity in marimo-team marimoCVE-2026-67618 0 marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operator API keys by embedding a malicious base_url in PEP-723 inline script metadata, which is merged into session configuration with higher precedence than the operator's own settings due to insufficient sanitization in sanitize_pyproject_dict. When an operator opens the crafted notebook and makes an AI request, marimo resolves the attacker-controlled base_url from the notebook config while falling back to the operator's OPENAI_API_KEY environment variable for authentication, transmitting the API key to the attacker-controlled endpoint without requiring any cell execution. Join the discussion | CVE Database V5 | 08/04/2026, 14:30:48 UTC Added: 08/04/2026, 14:56:55 UTC |
Showing 1 to 1 of 1 result