SB20260417102 - Unintended Proxy or Intermediary in Marimo



SB20260417102 - Unintended Proxy or Intermediary in Marimo

Published: April 17, 2026

Security Bulletin ID SB20260417102
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Unintended Proxy or Intermediary (CVE-ID: N/A)

The vulnerability allows a remote attacker to access internal services on the local machine.

The vulnerability exists due to proxying without authentication in the /mpl/{port}/ endpoint when handling unauthenticated requests to arbitrary local ports. A remote attacker can send crafted requests to the proxy endpoint to access internal services on the local machine.

The endpoint is exposed without authentication on default installations and can proxy traffic to services speaking web sockets, HTTP, or ASGI on the local machine.


Remediation

Install update from vendor's website.