Description
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SSRF to internal services
Action: Apply Patch
AI Analysis

Impact

Metabase is vulnerable when it accepts GeoJSON URLs containing the unspecified address 0.0.0.0. This omission allows an attacker to insert a malicious GeoJSON entry that points to the loopback interface; when the application subsequently fetches the data, it performs an internal request to 0.0.0.0. The response from the loopback service is then returned to the originating client, enabling unauthenticated attackers to observe internal service output or carry out further exploitation. The weakness is a Server‑Side Request Forgery (CWE‑918).

Affected Systems

Metabase installations running any release up to and including 0.63.18 are affected. The vulnerability is present in the open‑source version, as indicated by the vendor/product identification. No other specific product variants or versions are listed in the release notes provided.

Risk and Exploitability

The CVSS score is 6.9 and the EPSS score is below 1%; it is not in the CISA KEV catalog. The attack requires no authentication and can be performed through the GeoJSON API, which the data suggests is the intended attack path. The likely attack vector is an unauthenticated HTTP request that creates or modifies a GeoJSON entry pointing to 0.0.0.0. The low exploitation probability indicates limited active exploitation in the wild, but the mechanism remains straightforward.

Generated by OpenCVE AI on September 18, 2026 at 00:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Metabase release newer than 0.63.18, where the GeoJSON URL validation has been corrected.
  • If an upgrade cannot be applied immediately, block outbound connections from the Metabase instance to 127.0.0.1 and 0.0.0.0 using firewall or network policies to prevent the application from accessing the loopback interface.
  • Monitor GeoJSON API usage and review any new entries that reference 0.0.0.0 before allowing them to be persisted.

Generated by OpenCVE AI on September 18, 2026 at 00:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
Title Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass
First Time appeared Metabase
Metabase metabase
Weaknesses CWE-918
CPEs cpe:2.3:a:metabase:metabase:*:*:*:*:*:*:*:*
Vendors & Products Metabase
Metabase metabase
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Metabase Metabase
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:42:23.657Z

Reserved: 2026-09-16T19:55:02.080Z

Link: CVE-2026-92813

cve-icon Vulnrichment

Updated: 2026-09-17T13:42:14.720Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:31.163

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92813

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:45:16Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)