VYPR
Medium severity4.3NVD Advisory· Published Aug 14, 2025· Updated Jun 17, 2026

CVE-2025-55673

CVE-2025-55673

Description

When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user.

This issue affects Apache Superset: before 4.1.3.

Users are recommended to upgrade to version 4.1.3, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
apache-supersetPyPI
< 4.1.3.post14.1.3.post1

Affected products

10

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.