marimo Glance renders marimo notebooks inline on code-hosting sites. Notebook source is compressed into the page URL fragment and run by the in-browser WASM runtime, so it never leaves your machine.
Found something? Open a private advisory on GitHub or email security [at] marimo [dot] io. A description and steps to reproduce are all we need.
We'll acknowledge within 3 business days and keep you posted, and we're happy to credit you in the advisory.
This covers the marimo Glance extension and the packages in this repo. For marimo itself, the marimo.app playground, or molab, use the marimo security policy.