CVE-2023-37941Medium· 6.6▾ TwilightPoC availableApache Superset Deserialization of Untrusted Data vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 36.3 · likelihood 7.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
29%
29% → 35%
1 GitHub repo · Metasploit ×1
If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is typically only accessible directly by the system administrator and the superset process itself. Gaining access to that database should be difficult and require significant privileges. This vulnerability impacts Apache Superset versions 1.5.0 up to and including 2.1.0. Users are recommended to upgrade to version 2.1.1 or later.
apache-superset >= 1.5.0, < 2.1.1Upgrade to a patched release:
apache-superset 2.1.1Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-39265Medium· 6.5Apache Superset Improper Input Validation vulnerability
CVE-2026-23980MediumApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2024-34693Medium· 6.8Apache Superset server arbitrary file read
CVE-2023-27524High· 8.9Apache superset missing check for default SECRET_KEY
CVE-2024-39887Medium· 4.3Apache Superset vulnerable to improper SQL authorization
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections