VYPR
Medium severity4.9NVD Advisory· Published Sep 16, 2026

CVE-2026-92813

CVE-2026-92813

Description

Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Metabase/Metabasereferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.63.18

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.