• Sources: primary, report, advisory, discussion
  • Summary: Framework notified all customers that names, email addresses, phone numbers, and physical addresses were stolen. Framework attributes the breach to a flaw in the hosted Metabase business intelligence platform, which held the customer databases on Metabase cloud servers, and Framework never ran the vulnerable software itself. TechCrunch reports that Metabase disclosed in its own blog post that it was hacked through an unknown security flaw, a zero-day. Framework's notice names no CVE or advisory, so the link to GHSA-vwf4-m7j8-wcjf specifically is not confirmed. Metabase published GHSA-vwf4-m7j8-wcjf on 2026-08-06, an unauthenticated SQL injection rated CVSS 10.0 with exploitation confirmed in the wild, patched in releases spanning x.58.24 to x.63.5.
  • Why it matters: A flaw in a third-party analytics vendor exposed a customer database at a company with no way to patch it, which is the vendor-dependency case that asset inventories usually miss.
  • Follow-up: Watch for Framework or Metabase confirming that the breach is GHSA-vwf4-m7j8-wcjf, and for the count of other affected tenants.

send feedback on this story