Apache SupersetGHSA-mhpq-m962-mg92
Apache Superset allows authenticated users to discover metadata about datasources they don't have permission to access
MediumCVE-2025-55675 · Published Aug 14, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| apache-superset PyPI | < 5.0.0 | 5.0.0 |
Details and references
Apache Superset contains an improper access control vulnerability in its /explore endpoint. A missing authorization check allows an authenticated user to discover metadata about datasources they do not have permission to access. By iterating through the datasource_id in the URL, an attacker can enumerate and confirm the existence and names of protected datasources, leading to sensitive information disclosure. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-285
- Also known as
- BIT-superset-2025-55675, CVE-2025-55675, PYSEC-2026-1186
More Apache Superset advisories
All Apache Superset| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 142025 | Apache Superset data query improperly discloses database schema information to low-privileged guest user CVE-2025-55673Mediumfixed in 4.1.3.post1 | Medium | 4.1.3.post1 |
| Aug 142025 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability CVE-2025-55672Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| Aug 142025 | Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions CVE-2025-55674Mediumfixed in 5.0.0 | Medium | 5.0.0 |
| May 302025 | Apache Superset: Improper authorization bypass on row level security via SQL Injection CVE-2025-48912Highfixed in 4.1.2 | High | 4.1.2 |
| May 132025 | Apache Superset Allows Ownership Takeover CVE-2025-27696Medium8.8fixed in 4.1.2 | Medium8.8 | 4.1.2 |
| Feb 24 | Apache Superset Improper Authorization allows low-privileged users to bypass access controls CVE-2026-23982Highfixed in 6.0.0 | High | 6.0.0 |