SB20260417102 - Unintended Proxy or Intermediary in Marimo
Published: April 17, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Unintended Proxy or Intermediary (CVE-ID: N/A)
The vulnerability allows a remote attacker to access internal services on the local machine.
The vulnerability exists due to proxying without authentication in the /mpl/{port}/ endpoint when handling unauthenticated requests to arbitrary local ports. A remote attacker can send crafted requests to the proxy endpoint to access internal services on the local machine.
The endpoint is exposed without authentication on default installations and can proxy traffic to services speaking web sockets, HTTP, or ASGI on the local machine.
Remediation
Install update from vendor's website.