The /mpl/<port>/<route> endpoint, which is accessible without authentication on default Marimo installations allows for external attackers to reach internal services and arbitrary ports.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view