A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.
The CVSS‑9.3 vulnerability allows unauthenticated remote code execution on exposed Marimo servers and was exploited in the wild shortly after disclosure, Sysdig says. A critical pre-authentication ...