Apache SupersetGHSA-fj97-2v9x-w5m4
Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability
MediumCVE-2025-55672 · Published Aug 14, 2025 · updated Jul 7, 2026
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 5.0.0 | 5.0.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-80
- Also known as
- BIT-superset-2025-55672, CVE-2025-55672, PYSEC-2026-1176
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections | High | 6.0.0 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions | Medium | 5.0.0 |
| Aug 142025 | Apache Superset: improper access control | Medium | 5.0.0 |
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover | Medium8.8 | 4.1.2 |