A vulnerability labeled as problematic has been found in marimo-team marimo up to 0.23.8. This vulnerability affects the function
__new__ of the component Link Handler. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-54386. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.