CVE-2025-55672

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
14/08/2025
Last modified:
04/11/2025

Description

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset&amp;#39;s chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column&amp;#39;s label. The payload is not properly sanitized and gets executed in the victim&amp;#39;s browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user.<br /> <br /> This issue affects Apache Superset: before 5.0.0.<br /> <br /> Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* 5.0.0 (excluding)