When notebook metadata becomes an attack surface
What jumps out to me is not the specific Marimo bug so much as the pattern: notebook formats keep accreting “helpful” configuration, and that config keeps behaving like trusted code. That is a bad bargain. If a notebook can smuggle an MCP command, an AI base URL, or even terminal access through metadata, then the file itself is no longer just content — it is an execution container with extra steps. I’m also mildly skeptical of how cleanly these stories get separated into neat buckets: one CVE fo
papoo.work