Incident Published: Jun 6, 2026

Sysdig marimo: When an LLM Agent Drives Post-Exploitation After RCE

Sysdig observed a May 10 intrusion where an attacker used CVE-2026-39987 to reach an internet-facing marimo notebook (marimo is a Jupyter-like interactive Python notebook that runs in the browser), then let an LLM agent drive post-exploitation: credential harvesting, AWS Secrets Manager access, SSH through a bastion, and an internal PostgreSQL dump. The lesson is not only to patch marimo. AI and data-science runtimes need early authentication, narrow credentials, egress limits, segmentation, and telemetry that follows goals rather than fixed command sequences.

Remote Code ExecutionCredential TheftRuntime IsolationCredential GovernanceAgentic AI
7 applicable AIDEFEND defenses
Source: AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots 
Author: Michael Clark (Sysdig Threat Research Team)
Original article: May 26, 2026

Threat Analysis

  • Initial access was a notebook shell. The attacker connected to /terminal/ws on a vulnerable, internet-reachable marimo instance and gained command execution through CVE-2026-39987.
  • The first pivot was credential harvest. The session read environment files, .env paths, process environments, and ~/.aws/credentials, then used harvested AWS keys to call STS and Secrets Manager.
  • The second pivot turned a secret into SSH reach. The attacker retrieved an SSH private key, used Cloudflare Workers as an egress pool, and opened eight short SSH sessions to a downstream bastion.
  • The agent signature appears in the command stream. Sysdig cites a leaked planning comment, delimiter-heavy shell blocks, bounded output captures, a single psql heredoc, and values lifted from prior tool output.
  • The payload was an internal database dump. The bastion phase enumerated PostgreSQL tables, guessed high-value AI-workflow tables, and exfiltrated schema and contents in under two minutes.

Applicable AIDEFEND Defenses (7)

AID-H-004.001
User & Privileged Access Management
Very High
The marimo terminal WebSocket and notebook are human operator surfaces. Require an authenticated user, MFA, least-privilege roles, and privileged-session controls before a person can create a terminal or execute notebook code, so an anonymous browser request cannot become a host shell. Workload authentication for downstream model, data-store, or MLOps calls remains AID-H-004.002's separate boundary.
AID-I-001.004
Sandbox Network Egress Restrictions
Very High
The chain depended on outbound reach from the compromised runtime to cloud APIs, Cloudflare Workers, SSH, and the internal database path. Default-deny egress for notebook and code-execution sandboxes would sharply reduce callback traffic, credential replay, and lateral movement after RCE.
AID-M-001.005
Public AI Endpoint & Agent-Service Exposure Discovery
Very High
Marimo was reachable from the public Internet, so probe organization-owned notebook and agent routes from an untrusted vantage point without inherited credentials. Reconcile each route to ownership, exposure intent, and authentication posture and emit an exact finding for unknown, ownerless, or unexpectedly public terminals; another control owns remediation.
AID-I-002.001
Internal AI Network Segmentation
High
The intrusion became severe because a compromised data-science runtime could help reach AWS Secrets Manager, a bastion, and an internal PostgreSQL database. Network segmentation and microsegmentation should prevent public-facing AI notebooks from directly reaching high-value internal data stores or administrative jump paths.
AID-H-003.010
Deployed AI Software Vulnerability Remediation Lifecycle
High
Reconcile every deployed marimo notebook version with the terminal WebSocket advisory, rebuild and stage the fixed release, and verify that no vulnerable runtime remains internet-reachable or in service. This directly owns software remediation and fleet completion.
AID-D-005.003
Proactive AI Threat Hunting
High
Use a hypothesis-driven hunt to connect terminal WebSocket access, credential-file enumeration, STS and Secrets Manager calls, Cloudflare Workers fan-out, short SSH sessions, and PostgreSQL dumps across notebook, cloud, endpoint, identity, and database telemetry. The value is finding the same attacker objective even when an agent composes a different command sequence each time, rather than relying on one predefined signature.
AID-E-001.001
Root & Long-Lived Credential Object Eviction
Medium
The attacker moved by reusing AWS keys, SSH material, and database passwords found after initial access. Once a marimo runtime has been public or compromised, teams need immediate rotation for cloud credentials, API keys, database passwords, SSH keys, and any long-lived service credentials reachable from the process.

What Defenders Should Do Now

  • Upgrade marimo to 0.23.0 or later. If upgrade is delayed, restrict access to /terminal/ws, disable the terminal feature, and place notebook services behind strong authentication and private network paths.
  • Inventory internet-facing notebooks, AI sandboxes, data-science UIs, and MCP or agent development surfaces. Record whether each one can execute shell commands, read environment variables, or reach cloud APIs.
  • Rotate credentials on any marimo host that was exposed. Include AWS keys, API keys, database passwords, SSH keys, local secrets, and service credentials mounted into the runtime.
  • Move notebook and code-execution workloads into sandboxes with default-deny egress. Add only reviewed outbound destinations, and keep cloud APIs, bastions, and internal databases off the default route.
  • Segment internal databases and bastions away from AI experimentation hosts. A public notebook should not be able to discover, SSH into, or query production data stores without an explicit, logged path.
  • Add detections for credential-file reads, secretsmanager:GetSecretValue bursts, per-request egress pools, unusual SSH fan-out, delimiter-heavy shell probes, and database dumps after notebook activity.

Conclusion

Sysdig's marimo case matters because the LLM did not invent a new exploit. It made post-exploitation cheaper, faster, and more adaptive after a conventional RCE. AIDEFEND  maps the defense to early service authentication, sandbox egress limits, internal segmentation, posture baselines, AI-aware monitoring, and credential rotation. The durable goal is to make AI notebook compromise a contained incident, not a shortcut to cloud secrets and internal databases that opens the door to far greater damage.