Vulnerability in Marimo versions before 0.23.15 involving an attacker-controlled AI base_url supplied through notebook metadata. When an operator opens a malicious notebook and later makes an AI request, the configured endpoint receives the operator's API key without requiring cell execution. CVSS score 7.1. Disclosed by VulnCheck on August 4, 2026.