CVE-2026-92813: Metabase
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
Affected products
- Metabase Metabase: up to and including 0.63.18
Published 2026-09-16. Last modified 2026-09-22.