rootpwn

medium · CVSS v3 4.9 · CVSS v4 6.9

CVE-2026-92813

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing una…

Description

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

Scores

Severity
medium
CVSS v2
6.1
CVSS v3
4.9
CVSS v4
6.9
EPSS

← All CVEs