This issue affects Apache Superset: before 5.0.0.
Users are recommended to upgrade to version 5.0.0, which fixes the issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24819 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability |
Github GHSA |
GHSA-fj97-2v9x-w5m4 | Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 18 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Fri, 15 Aug 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache superset |
|
| Vendors & Products |
Apache
Apache superset |
Thu, 14 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 Aug 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue. | |
| Title | Apache Superset: Stored XSS on charts metadata | |
| Weaknesses | CWE-80 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-11-04T21:13:10.307Z
Reserved: 2025-08-13T12:38:31.381Z
Link: CVE-2025-55672
Updated: 2025-11-04T21:13:10.307Z
Status : Modified
Published: 2025-08-14T14:15:34.347
Modified: 2025-11-04T22:16:30.710
Link: CVE-2025-55672
No data.
OpenCVE Enrichment
Updated: 2025-08-15T08:17:31Z
EUVD
Github GHSA