Human Hacker Beats AI-Speed Attacks: Marimo Notebook Flaw Exploited in Eight Seconds
Security researchers at Sysdig have detailed an attack on Marimo, a notebook platform commonly used alongside machine learning pipelines, that saw a human operator move from initial compromise to full cloud access in just eight seconds. The flaw, CVE-2026-39987, is a pre-authentication remote code execution bug affecting Marimo versions up to 0.20.4, fixed in version 0.23.0. It allowed anyone to open a connection to the platform's terminal WebSocket endpoint and get an interactive shell without credentials.
Because Marimo notebooks often run on hosts with GPU access, sensitive datasets, and cloud credentials, a compromised notebook can become a direct route into a victim's cloud environment. In this case, the attacker harvested AWS credentials from the host and its Redis backend, eventually recovering an SSH private key from AWS Secrets Manager that unlocked access to an internet-facing bastion host. While the final break-in took only seconds, Sysdig noted the attacker had spent roughly four hours earlier building and testing a custom Python toolkit, then executed the polished attack chain in one go.
What makes this case notable is that researchers had planted a hidden trap designed to catch AI-driven attackers: a file instructing any AI model that read it to leave a telltale marker. Every automated AI agent tested against this flaw triggered the trap, but this human operator, despite reviewing the same file twice, never did, giving Sysdig its clearest evidence yet of a purely human-led attack matching AI-level speed.