GHSA-vhcq-xc7j-xfj8MediumCVSS 4.9

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

🔗 References (6)