CVSS 10.0

Your Business Intelligence Platform Just Handed Attackers Your Customer List. And It’s Worse Than You Think.

Metabase’s unauthenticated SQL injection in the password reset endpoint (CVSS 10.0) has already been used in the wild against Framework customers. If you use Metabase, treat this as an active breach, not a patch. Check your logs, rotate credentials, and assume your data is already exposed.