Skip to content
Apache SupersetGHSA-8w7f-8pr9-xgwj

Apache Superset: Improper authorization bypass on row level security via SQL Injection

HighCVE-2025-48912 · Published May 30, 2025 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 4.1.24.1.2
Details and references

An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.

CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
BIT-superset-2025-48912, CVE-2025-48912, PYSEC-2026-1164

More Apache Superset advisories

All Apache Superset
DateAdvisory
May 132025Apache Superset Allows Ownership Takeover
CVE-2025-27696Medium8.8fixed in 4.1.2
Aug 142025Apache Superset data query improperly discloses database schema information to low-privileged guest user
CVE-2025-55673Mediumfixed in 4.1.3.post1
Aug 142025Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
CVE-2025-55672Mediumfixed in 5.0.0
Aug 142025Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
CVE-2025-55674Mediumfixed in 5.0.0
Aug 142025Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
CVE-2025-55675Mediumfixed in 5.0.0
Dec 122024Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access
CVE-2024-55633High6.5fixed in 4.1.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.