• Sources: advisory, second advisory, forum discussion, discussion
  • Summary: Metabase published two critical advisories on 2026-08-06. GHSA-vwf4-m7j8-wcjf is an unauthenticated SQL injection rated CVSS 10.0 with exploitation confirmed in the wild, and GHSA-r8h2-qpfx-mx59 is rated 9.6 and reachable through any publicly shared dashboard carrying a field-filter parameter. Both reach administrator access and the stored credentials for every database the instance connects to, and patched releases span six major lines from x.58.24 to x.63.5. The advisory names /api/session/reset_password as the vulnerable endpoint and states that blocking it is a temporary workaround for anyone who cannot upgrade immediately.
  • Why it matters: An unauthenticated request reaches administrator access and the stored credentials for every connected database, and exploitation is confirmed in the wild. The advisory conditions the post-upgrade steps on /api/session/reset_password being publicly accessible, in which case it directs operators to revoke sessions, review API keys and admin accounts, and rotate the credentials for every connected database.
  • Follow-up: Framework Computer customers posting on Framework's own community forum quote a notification email attributing a breach to a Metabase zero-day. Framework published nothing of its own, so the advisories and that breach are carried here as separate facts. Confirm the link when a primary account appears.

send feedback on this story