Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked
π Search
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Modehttps://thehackernews.com/2026/08/marimo-notebook-flaw-could-run-mcp.html
Show HN: Square Sketch β A vector graphics editor with a modeless interfacehttps://squaresight.io/en/sketch/index.html
Article URL: https://squaresight.io/en/sketch/index.html Comments URL: https://news.ycombinator.com/item?id=49432621 Points: 1 # Comments: 1
How to understand this heat wave (as told by NPR's senior climate editor)https://www.npr.org/2026/08/25/nx-s1-5940053/heat-wave-extreme-forecast-climate
As the senior climate editor at NPR, when extreme weather impacts us, I often send out guidance to the newsroom to help everyone understand the role of climate change. Here's what I tell them.
