Skip to content
Apache SupersetGHSA-fm4q-j8g4-c9j4

Apache Superset Improper Input Validation vulnerability

Medium6.5CVE-2023-39265 · Published Sep 6, 2023 · updated Jul 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
<= 2.1.0No fix yet
Details and references

Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database for its metadata (not advised for production use) it could result in more severe vulnerabilities related to confidentiality and integrity. This vulnerability exists in Apache Superset versions up to and including 2.1.0.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-20
Also known as
BIT-superset-2023-39265, CVE-2023-39265, PYSEC-2026-1177

More Apache Superset advisories

All Apache Superset
DateAdvisory
Sep 62023Apache Superset Server Side Request Forgery vulnerability
CVE-2023-36388Medium4.3no fix yet
Sep 62023Apache Superset has improper default REST API permission for Gamma users
CVE-2023-36387Medium5.4no fix yet
Sep 62023Apache Superset users may incorrectly create resources using the import charts feature
CVE-2023-27526Medium4.3no fix yet
Sep 62023Apache Superset may expose internal traces on REST API endpoints
CVE-2023-39264Medium4.3no fix yet
Sep 62023Apache Superset vulnerable to improper data authorization
CVE-2023-27523Medium5.0no fix yet
Sep 62023Apache Superset has incorrect authorization check
CVE-2023-32672Medium4.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.