CVE-2026-39987: Marimo RCE Exploited in Hours — AI Toolchain Attack Surface
A pre-authenticated remote code execution flaw in Marimo was exploited within 10 hours of disclosure. The attacker needed no public exploit code — only the advisory text. Here is what happened and why AI development tools are a growing attack surface.