Metabase Patches Zero-Day SQL Injection Exploited in the Wild
This digest was compiled by AI from multiple sources — links to the originals are below.

Metabase disclosed that its Cloud platform was breached via a maximum-severity SQL injection zero-day vulnerability. The company immediately blocked the attack endpoints, patched the flaw, and automatically upgraded cloud instances. Self-hosted users who expose the /api/session/reset_password endpoint to the public internet remain at risk.
The Vulnerability
Metabase assigned a CVSS 10 severity score to the zero-day, which still has no CVE identifier. The flaw affects Metabase versions 1.58 and later. According to a GitHub advisory, exploitation allows a remote attacker to inject SQL statements, gaining administrator access to the instance. From there, the attacker could change configuration, steal stored credentials for connected databases, and export data.
Who Is Affected
Metabase Cloud customers were automatically upgraded and require no action. Self-hosted users who expose the /api/session/reset_password endpoint on the public internet remain vulnerable. SANS Internet Storm Center's Johannes Ullrich noted that Metabase typically exposes its API on port 3000, and most installations likely have open network access. "There is no obvious reason not to expose the reset password API, as users may need it," Ullrich said. It is unclear whether the attacks were limited to Metabase Cloud or also compromised self-hosted instances.
What's Next
Metabase has not yet disclosed the full scope of the attack or whether self-hosted instances were compromised. Organizations using databases connected to Metabase could face credential theft if exploitation went undetected.
3 sources
Metabase Patches Zero-Day SQL Injection Exploited in the Wild



