“We recently identified that Metabase Cloud was attacked by someone utilizing an unknown ("0-day") security vulnerability in versions 1.58 and above,” Metabase CEO Sameer Al‑Sakran wrote, a blunt notification that accompanied the company’s confirmation of active exploitation and a CVSS 10.0 severity rating.
Metabase Cloud and self‑hosted installations
Metabase said the attacker used a previously unknown SQL injection vulnerability to breach customer instances of its analytics product. The company reported it blocked the endpoints used for the attack and “immediately rolled out a fix.” Metabase Cloud customers, the company said, have already been upgraded and patched; organizations running self‑hosted installations must update manually.
The vulnerability: unauthenticated SQL injection, rated Critical (CVSS 10.0)
Metabase’s security advisory describes the flaw as “an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer's instance.” The advisory warns that an attacker who gains that access can change application configuration, steal stored credentials for connected databases, read any data accessible through those connections, and export data. Metabase has not assigned a CVE identifier as of its advisory but rated the issue Critical and confirmed it has been actively exploited.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildConfirmed customer impacts: Framework, Tally, and LexisNexis
Several organizations have disclosed they were impacted. Laptop maker Framework said attackers who compromised its Metabase instance stole customer information including full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers, and company names; Framework for Business customers may also have had company name, phone number, VAT, EIN, and billing email address exposed. Framework said Metabase notified the company on August 6 that its instance had been vulnerable and that attackers accessed it on August 3.
Form builder Tally reported its Metabase analytics environment was compromised on August 3. Tally said the attackers reached user email addresses and “your password as a cryptographic hash.” Tally added the attackers did not reach its forms or the answers submitted to them, which are stored separately. BleepingComputer asked Tally about the hashing algorithm and whether hashes were salted but had not received a response at the time of publication.
LexisNexis sent customers an update saying it was impacted by “unusual activity on servers that are hosted and managed by a third‑party vendor,” and that the company disconnected from those third‑party systems to protect customers. The company’s notice said the Metabase API was impacted; LexisNexis said it is working with a cybersecurity forensic firm and that it is unclear whether customer data was exposed.
Detection, mitigations, and available patches
- Metabase fixed the SQLi vulnerability in patched releases across affected branches 0.58 through 0.63. The minimum safe releases listed are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
- As a temporary measure, organizations unable to upgrade immediately are advised to block access to the '/api/session/reset_password' endpoint until they can apply the update.
- Metabase recommends self‑hosted customers immediately upgrade, revoke all active user sessions, review API keys and administrator accounts for unauthorized changes, rotate credentials for connected databases, and inspect logs and query history for signs of compromise.
- The company says attacks can be identified by a POST request to /api/session/reset_password returning a 400 status code, followed by a successful GET request to /api/user/current; Metabase warns that system logs showing these entries have likely been compromised.
What this means for technologists, procurement leaders, and affected customers
- Technologists and security teams: prioritize immediate upgrades to the listed safe releases, block the specified endpoint if unable to patch, and perform the prescribed post‑incident steps — revoke sessions, rotate connected‑database credentials, and comb logs and query history for evidence of data access.
- Procurement and vendor managers: review which vendor offerings depend on Metabase or third‑party Metabase hosting and confirm patching status and incident response procedures with providers — LexisNexis’ notice underscores that third‑party hosting can propagate impact to enterprise services.
- Affected customers and end users: check breach notifications from vendors tied to Metabase instances (Framework and Tally have disclosed impacts), follow vendor guidance about password resets and monitoring, and watch for direct communications about what specific fields were exposed.
Metabase’s swift patching and endpoint blocks are concrete steps, but the company has not published a CVE or a count of customer instances accessed. The public record so far names Framework, Tally, and a LexisNexis vendor disruption; whether additional customers were accessed and how many records were exfiltrated remains to be disclosed. For organizations using Metabase — cloud or self‑hosted — the immediate course is simple and stark: assume exposure risk until you have applied the fixes, rotated credentials, and confirmed logs and queries show no unauthorized access.




