Apache Superset: Metadata exposure in embedded charts
Vulnerability Description
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This issue affects Apache Superset: before 4.1.3. Users are recommended to upgrade to version 4.1.3, which fixes the issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-55673
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Pedro Sousa
- Daniel Gaspar
More from Apache Software Foundation
View All →Affected Vendor
Apache Software Foundation
View all reports →