oss-sec mailing list archives

CVE-2025-55672: Apache Superset: Store XSS on charts metadata


From: Daniel Gaspar <dpgaspar () apache org>
Date: Thu, 14 Aug 2025 11:36:39 +0000

Severity: 

Affected versions:

- Apache Superset before 5.0.0

Description:

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated 
user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly 
sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session 
hijacking or the execution of arbitrary commands on behalf of the user.

This issue affects Apache Superset: before 5.0.0.

Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Credit:

Pedro Sousa (coordinator)
Jobar (finder)
Mehmet Yavuz (remediation developer)

References:

https://www.cve.org/CVERecord?id=CVE-2025-55672


Current thread: