Impact
Metabase is an open‑source business intelligence and embedded analytics tool. The vulnerability, rooted in the Snowflake JDBC driver, allows an arbitrary file write to any location on the host when a Metabase user with permission to create or edit a Snowflake database connection points the tool to an attacker‑controlled server. The flaw is present in Metabase releases from 1.54.0 up through 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4. An attacker can overwrite Metabase’s own JDBC driver or other files, causing the Metabase process to execute malicious code, leading to remote code execution that compromises confidentiality, integrity, and availability. This is a classic CWE‑73 arbitrary file write weakness.
Affected Systems
The affected product is the Metabase open‑source business intelligence and embedded analytics tool. Vulnerable releases include any Metabase 1.54 series version older than 1.54.24, any 1.55 series older than 1.55.24, any 1.56 series older than 1.56.25, any 1.57 series older than 1.57.19, any 1.58 series older than 1.58.14, any 1.59 series older than 1.59.10, or any 1.60 series older than 1.60.4; any installation running such a version that allows users to create or edit Snowflake database connections is at risk.
Risk and Exploitability
The CVSS score of 10 signals a critical severity, while the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation as of the latest assessment. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need permissions typically granted only to privileged administrators or power users to create or edit Snowflake database connections; the likely attack vector is via the Metabase web interface that allows such configuration. If such privileges exist, the flaw can be abused to write arbitrary files and trigger remote code execution, exemplifying a CWE‑73 weakness.
OpenCVE Enrichment