Apache SupersetGHSA-9g5x-mm39-wg9r
Apache Superset data query improperly discloses database schema information to low-privileged guest user
MediumCVE-2025-55673 · Published Aug 14, 2025 · updated Aug 13, 2026
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user. This issue affects Apache Superset: before 4.1.3. Users are recommended to upgrade to version 4.1.3, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 4.1.3.post1 | 4.1.3.post1 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-200
- Also known as
- BIT-superset-2025-55673, CVE-2025-55673, PYSEC-2026-1169
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections | High | 6.0.0 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability | Medium | 5.0.0 |
| Aug 142025 | Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions | Medium | 5.0.0 |
| Aug 142025 | Apache Superset: improper access control | Medium | 5.0.0 |
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover | Medium8.8 | 4.1.2 |