The CVSS‑9.3 vulnerability allows unauthenticated remote code execution on exposed Marimo servers and was exploited in the wild shortly after disclosure, Sysdig says.
Strapi plugins exploit Redis and PostgreSQL via postinstall scripts, enabling persistent access and data theft.