VYPR

Cube.js

by Cube

CVEs (4)

  • CVE-2022-23510CriDec 9, 2022
    risk 0.55cvss 9.6epss 0.01

    cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly introduced /v1/sql-runner endpoint. This issue has been resolved in version 0.31.24. Users are advised…

  • CVE-2026-25958HigFeb 9, 2026
    risk 0.43cvss 7.7epss 0.00

    Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token that leads to privilege escalation. This vulnerability is fixed in 1.5.13, 1.4.2, and 1.0.14.

  • CVE-2026-25957MedFeb 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. This vulnerability is fixed in 1.5.13 and 1.4.2.

  • CVE-2023-50709MedDec 13, 2023
    risk 0.35cvss 6.5epss 0.01

    Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint. The issue has been patched in `v0.34.34` and it's recommended that all…