Medium severity5.4NVD Advisory· Published Aug 14, 2025· Updated Jun 17, 2026
CVE-2025-55672
CVE-2025-55672
Description
A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user.
This issue affects Apache Superset: before 5.0.0.
Users are recommended to upgrade to version 5.0.0, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
apache-supersetPyPI | < 5.0.0 | 5.0.0 |
Affected products
8- osv-coords6 versionspkg:apk/chainguard/superset-4.1-entrypointpkg:apk/chainguard/superset-4.1-iamguarded-compatpkg:apk/wolfi/superset-4.1-entrypointpkg:apk/wolfi/superset-4.1-iamguarded-compatpkg:bitnami/supersetpkg:pypi/apache-superset
< 4.1.4-r2+ 5 more
- (no CPE)range: < 4.1.4-r2
- (no CPE)range: < 4.1.4-r2
- (no CPE)range: < 4.1.4-r2
- (no CPE)range: < 4.1.4-r2
- (no CPE)range: < 5.0.0
- (no CPE)range: < 5.0.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-fj97-2v9x-w5m4ghsaADVISORY
- lists.apache.org/thread/rvh7fdjfzxzjhcfwoz7twc2brhvochdjnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-55672ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/08/14/4nvdWEB
News mentions
0No linked articles in our index yet.