Apache SupersetGHSA-8w7f-8pr9-xgwj
Apache Superset: Improper authorization bypass on row level security via SQL Injection
HighCVE-2025-48912 · Published May 30, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 4.1.2 | 4.1.2 |
Details and references
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data. This issue affects Apache Superset: before 4.1.2. Users are recommended to upgrade to version 4.1.2, which fixes the issue.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- BIT-superset-2025-48912, CVE-2025-48912, PYSEC-2026-1164
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 132025 | Apache Superset Allows Ownership Takeover CVE-2025-27696Medium8.8fixed in 4.1.2 | Medium8.8 | 4.1.2 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user CVE-2025-55673Mediumfixed in 4.1.3.post1 | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability CVE-2025-55672Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Aug 142025 | Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions CVE-2025-55674Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Aug 142025 | Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access CVE-2025-55675Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Dec 122024 | Apache Superset: SQLLab Improper readonly query validation allows unauthorized write access CVE-2024-55633High6.5fixed in 4.1.0 | High6.5 | 4.1.0 |