Vulnerability Description
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/geo-chen/oss/blob/main/metabase.md#finding-2-geojson-ssrf-byp
- https://github.com/metabase/metabase
- https://github.com/metabase/metabase/blob/v0.61.2/src/metabase/geojson/api.clj#L
- https://www.vulncheck.com/advisories/metabase-through-0.63.18-ssrf-via-geojson-u
FAQ
What is CVE-2026-92813?
CVE-2026-92813 is a vulnerability with a CVSS score of 4.9 (MEDIUM). Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a maliciou...
How severe is CVE-2026-92813?
CVE-2026-92813 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92813?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.