Skip to content
Apache SupersetGHSA-wq8q-99p5-xfrw

Apache Superset Cross-site Scripting vulnerability

Medium4.3CVE-2023-43701 · Published Nov 27, 2023 · updated Jul 7, 2026

Improper payload validation and an improper REST API response type, made it possible for an authenticated malicious actor to store malicious code into Chart's metadata, this code could get executed if a user specifically accesses a specific deprecated API endpoint. This issue affects Apache Superset versions prior to 2.1.2.  Users are recommended to upgrade to version 2.1.2, which fixes this issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-superset
PyPI
< 2.1.22.1.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
BIT-superset-2023-43701, CVE-2023-43701, PYSEC-2026-1190

More Apache Superset advisories

All Apache Superset
Advisory
Apache Superset SQL injection vulnerability
Medium6.5Dec 19, 2023
Apache Superset - Elevation of Privilege
High7.3Nov 28, 2023
Apache Superset Open Redirect vulnerability
Medium5.4Nov 28, 2023
Apache Superset Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Medium4.3Nov 28, 2023
Apache Superset Allocation of Resources Without Limits or Throttling vulnerability
Medium6.5Nov 28, 2023
Apache Superset has Incorrect Default Permissions
Medium4.3Nov 27, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.