Vulnerability Description
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open-Metadata | Openmetadata | <= 1.4.4 |
Related Weaknesses (CWE)
References
- https://gist.github.com/javadk/0be29d2bb5a971bc09f3410659c83308ExploitThird Party Advisory
- https://github.com/open-metadata/OpenMetadata/blob/4b9145a9da7ed95b7f868ab9f351eProduct
- https://github.com/open-metadata/OpenMetadata/blob/4b9145a9da7ed95b7f868ab9f351eProduct
FAQ
What is CVE-2025-50468?
CVE-2025-50468 is a vulnerability with a CVSS score of 6.5 (MEDIUM). OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to ...
How severe is CVE-2025-50468?
CVE-2025-50468 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50468?
Check the references section above for vendor advisories and patch information. Affected products include: Open-Metadata Openmetadata.