apache-superset
PyPI66 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting apache-supersetpage 2 of 2
- CVE-2024-39887MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.0.22024-07-16
vulnerable: 0.34.0 ... 4.0.1 (54 versions)
An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL commands. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Supe…
- CVE-2024-53947CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.1.02024-12-09
vulnerable: 0.34.0 ... 4.1.0rc4 (58 versions)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL …
- CVE-2024-53948MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.1.02024-12-09
vulnerable: 0.34.0 ... 4.1.0rc4 (58 versions)
Generation of Error Message Containing analytics metadata Information in Apache Superset. This issue affects Apache Superset: before 4.1.0. Users are recommended to upgrade to version 4.1.0, which fixes the issue.
- CVE-2024-53949MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.02024-12-09
vulnerable: 2.0.0 ... 4.1.0rc4 (34 versions)
Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API. issue affects Apache Superset: from 2.0.0 before 4.1.0. Users are re…
- CVE-2024-55633MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.02024-12-12
vulnerable: 0.34.0 ... 4.1.0rc4 (58 versions)
Improper Authorization vulnerability in Apache Superset. On Postgres analytic databases an attacker with SQLLab access can craft a specially designed SQL DML statement that is Incorrectly identified as a read-only query, enabling its exe…
- CVE-2025-27696HIGHCVSS 8.8EG 8.8✓ Fixed in 4.1.22025-05-13
vulnerable: 0.34.0 ... 4.1.2rc1 (62 versions)
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended t…
- CVE-2025-48912MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.22025-05-30
vulnerable: 0.34.0 ... 4.1.2rc1 (62 versions)
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately gr…
- CVE-2025-55672MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.0.02025-08-14
vulnerable: 0.34.0 ... 5.0.0rc4 (72 versions)
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sani…
- CVE-2025-55673MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.1.3.post12025-08-14
vulnerable: 0.34.0 ... 4.1.3rc2 (65 versions)
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, …
- CVE-2025-55674MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.0.02025-08-14
vulnerable: 0.34.0 ... 5.0.0rc4 (72 versions)
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access t…
- CVE-2025-55675MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.0.02025-08-14
vulnerable: 0.34.0 ... 5.0.0rc4 (72 versions)
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterati…
- CVE-2026-23969MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.1.22026-02-24
vulnerable: 0.34.0 ... 4.1.2rc1 (62 versions)
Apache Superset utilizes a configurable dictionary, DISALLOWED_SQL_FUNCTIONS, to restrict the execution of potentially sensitive SQL functions within SQL Lab and charts. While this feature included restrictions for engines like PostgreSQL,…
- CVE-2026-23980MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.0.02026-02-24
vulnerable: 0.34.0 ... 6.0.0rc4 (77 versions)
Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where paramete…
- CVE-2026-23982MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.0.02026-02-24
vulnerable: 0.34.0 ... 6.0.0rc4 (77 versions)
An Improper Authorization vulnerability exists in Apache Superset that allows a low-privileged user to bypass data access controls. When creating a dataset, Superset enforces permission checks to prevent users from querying unauthorized da…
- CVE-2026-23983MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.0.02026-02-24
vulnerable: 0.34.0 ... 6.0.0rc4 (77 versions)
A Sensitive Data Exposure vulnerability exists in Apache Superset allowing authenticated users to retrieve sensitive user information. The Tag endpoint (disabled by default) allows users to retrieve a list of objects associated with a spec…
- CVE-2026-23984MEDIUMCVSS 6.5EG 6.5✓ Fixed in 6.0.02026-02-24
vulnerable: 0.34.0 ... 6.0.0rc4 (77 versions)
An Improper Input Validation vulnerability exists in Apache Superset that allows an authenticated user with SQLLab access to bypass the read-only verification check when using a PostgreSQL database connection. While the system effectively …
Check whether apache-superset is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for apache-superset CVEs against the assets you own.
Start Free Scan →