Interestingly, only a few days after writing this toot, I somehow wound up with an invitation to use the molab online notebooks from #Marimo (https://marimo.io/).

I am happy to announce that molab notebooks are indeed able to load and run #RDKit; this will help immensely for people like me who are stuck on using stuff from the browser due to various constraints.

marimo | a next-generation Python notebook

Explore data and build apps seamlessly with marimo, a next-generation Python notebook.

Marimo: Das Python-Notebook, das endlich Sinn ergibt

Schon mehrfach hatte ich in diesem Blog Kritzelheft über Marimo, den neuen Stern am Python-Notebook-Himmel berichtet. Und immer waren diese Berichte mit guten Vorsätzen pepflastert, die nie zur Ausführung kamen. Heute also in weiterer Anlauf. Schauen wir mal, was daraus wird. https://kantel.github.io/posts/2026060201_marimo_introduction/ #Python #Marimo #Py5

⚠️ LLM-Agent bei realem Angriff: Nach Breach eines Marimo-Notebooks via CVE-2026-39987 (Pre-Auth RCE ≤0.20.4) stahlen Angreifer Cloud-Credentials, einen SSH-Key aus AWS Secrets Manager und exfiltrierten eine PostgreSQL-DB über 8 SSH-Sessions in unter 2 Minuten.

#CyberSecurity #Marimo #CVE202639987

- omg how am I only thinking of astral's #uv and #ruff now?? It is so great, much better than anything else. I was very sad that astral was bought by openai 🤖
- I also really dislike Jupyter notebooks and hate how much they are being (ab)used. I'm trying #marimo which I do like but I find it hard to share analyses with others internally. I'll find my way, but I do miss RStudio's native quarto integration (i know quarto also does python but in reality it hasn't yet worked out for me)

n/n

CVE Alert: CVE-2026-39987 - marimo-team - marimo - RedPacket Security

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks

RedPacket Security
Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face

Hackers are exploiting a critical vulnerability in Marimo reactive Python notebook to deploy a new variant of NKAbuse malware hosted on Hugging Face Spaces.

BleepingComputer

Hackers exploit Marimo flaw to spread NKAbuse malware via Hugging Face

Hackers are exploiting a critical flaw in Marimo's reactive Python notebook to spread a new variant of NKAbuse malware, sneaking malicious payloads onto Hugging Face Spaces, a popular platform for sharing machine learning models. This alarming attack highlights the need for vigilance when it comes to defending against malware…

https://osintsights.com/hackers-exploit-marimo-flaw-to-spread-nkabuse-malware-via-hugging-face?utm_source=mastodon&utm_medium=social

#Marimo #NkabuseMalware #HuggingFace #MalwareOperations #EmergingThreats

Hackers exploit Marimo flaw to spread NKAbuse malware via Hugging Face

Hackers exploit Marimo flaw to spread NKAbuse malware via Hugging Face, learn how to defend against this critical vulnerability now and protect your systems from attack.

OSINTSights
Critical Marimo pre-auth RCE flaw now under active exploitation

A critical pre-authentication remote code execution (RCE) vulnerability in Marimo is now under active exploitation, leveraged for credential theft.

BleepingComputer

Marimo Flaw Exploited for Credential Theft in Active Attacks

A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

https://osintsights.com/marimo-flaw-exploited-for-credential-theft-in-active-attacks?utm_source=mastodon&utm_medium=social

#Marimo #CredentialTheft #RemoteCodeExecution #Preauthentication #ActiveExploitation

Marimo Flaw Exploited for Credential Theft in Active Attacks

Marimo vulnerability exploited in active attacks for credential theft, learn how to protect your organization now from this critical pre-authentication RCE flaw.

OSINTSights
CVE-2026-39987: Marimo RCE exploited in hours after disclosure

A critical flaw, tracked as CVE-2026-39987, in the open-source Python notebook tool Marimo was exploited within 10 hours of disclosure.

Security Affairs