Apache SupersetGHSA-fxgf-3xh6-m2pp
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
MediumCVE-2025-55674 · Published Aug 14, 2025 · updated Jul 7, 2026
A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leading to the disclosure of sensitive database information like the software version. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 5.0.0 | 5.0.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- BIT-superset-2025-55674, CVE-2025-55674, PYSEC-2026-1178
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections | High | 6.0.0 |
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability | Medium | 5.0.0 |
| Aug 142025 | Apache Superset: improper access control | Medium | 5.0.0 |
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover | Medium8.8 | 4.1.2 |