CVE-2021-41277Critical· 10.0▾ Hadal⚠ Exploited in the wildPoC availableMetabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (inclu…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 55 · likelihood 19.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Dec 3, 2024
Last analysed / modified upstream
97%
12 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Nov 12, 2024. Federal remediation due Dec 3, 2024. View catalog ↗
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (admin->settings->maps->custom maps->add a map) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
metabase = 0.40.0metabase = 0.40.1metabase = 0.40.2metabase = 0.40.3metabase = 0.40.4metabase = 1.40.0metabase = 1.40.1metabase = 1.40.2metabase = 1.40.3metabase = 1.40.4Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92813Medium· 4.9Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services
CVE-2026-86116Medium· 6.5Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glossary entries
CVE-2024-24919High· 8.6Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades
CVE-2026-105707Medium· 5.3A security vulnerability has been detected in uptrace up to 2.1.0-beta.8
CVE-2026-105748Medium· 4.3Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
CVE-2026-105635High· 7.4Plane is an open-source project management tool