VulnerabilityAnalyzed
CVE-2025-5895
A vulnerability was found in Metabase 54.10.
LOW 2.1EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 4454ebbdc7719016bf80ca0f34859ce5cee9f6b0. It is recommended to apply a patch to fix this issue.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.61% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-1333
- Affected
- metabase/metabase
- Source
- cna@vuldb.com
References
- https://github.com/metabase/metabase/commit/4454ebbdc7719016bf80ca0f34859ce5cee9f6b0Patch
- https://github.com/metabase/metabase/pull/57011Exploit, Issue Tracking, Patch
- https://github.com/metabase/metabase/pull/57011#pullrequestreview-2792664135Exploit, Issue Tracking, Patch
- https://vuldb.com/?ctiid.311667Permissions Required, VDB Entry
- https://vuldb.com/?id.311667Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.585795Third Party Advisory, VDB Entry
- https://github.com/metabase/metabase/pull/57011Exploit, Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.