---
id: CVE-2021-41277
title: Metabase is an open source data analytics platform
summary: >-
  Metabase is an open source data analytics platform. In affected versions a
  security issue has been discovered with the custom GeoJSON map
  (`admin->settings->maps->custom maps->add a map`) support and potential local
  file inclusion (inclu…
severity: critical
cvss: 10
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L'
cwe:
  - CWE-200
  - CWE-22
vendor: metabase
product: metabase
affected:
  - metabase = 0.40.0
  - metabase = 0.40.1
  - metabase = 0.40.2
  - metabase = 0.40.3
  - metabase = 0.40.4
  - metabase = 1.40.0
  - metabase = 1.40.1
  - metabase = 1.40.2
  - metabase = 1.40.3
  - metabase = 1.40.4
published: '2021-11-17'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:10.807'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41277'
references:
  - url: >-
      https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0
    label: security-advisories@github.com
  - url: >-
      https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr
    label: security-advisories@github.com
  - url: >-
      https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41277
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2025-08-20T03:56:21.253891Z'
epss: 0.97178
epssPercentile: 0.99895
kev: true
kevDateAdded: '2024-11-12'
kevDueDate: '2024-12-03'
kevRansomware: false
exploits:
  github: 12
  githubRepos:
    - 'https://github.com/tahtaciburak/CVE-2021-41277'
    - 'https://github.com/Henry4E36/Metabase-cve-2021-41277'
    - 'https://github.com/kap1ush0n/CVE-2021-41277'
  nuclei:
    - CVE-2021-41277
  checkedAt: '2026-10-07T18:42:55.482Z'
ingestedAt: '2026-10-07T18:42:20.873Z'
---

## Overview

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

## Affected

- `metabase = 0.40.0`
- `metabase = 0.40.1`
- `metabase = 0.40.2`
- `metabase = 0.40.3`
- `metabase = 0.40.4`
- `metabase = 1.40.0`
- `metabase = 1.40.1`
- `metabase = 1.40.2`
- `metabase = 1.40.3`
- `metabase = 1.40.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
