CVE-2025-55674Medium▾ SunlitApache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leading to the disclosure of sensitive database information like the software version.
This issue affects Apache Superset: before 5.0.0.
Users are recommended to upgrade to version 5.0.0, which fixes the issue.
apache-superset < 5.0.0Upgrade to a patched release:
apache-superset 5.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23984HighApache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
CVE-2026-23983LowApache Superset allows authenticated users to view sensitive data without explicit permissions
CVE-2026-23980MediumApache Superset allows privileged users to conduct error-based SQL Injection
CVE-2026-23969MediumApache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
CVE-2026-23982HighApache Superset Improper Authorization allows low-privileged users to bypass access controls
CVE-2024-24779Medium· 5.0Apache Superset: Improper data authorization when creating a new dataset