CVE-2025-55673
Severity CVSS v4.0:
MEDIUM
Type:
CWE-200
Information Leak / Disclosure
Publication date:
14/08/2025
Last modified:
04/11/2025
Description
When a guest user accesses a chart in Apache Superset, the API response from the /chart/data endpoint includes a query field in its payload. This field contains the underlying query, which improperly discloses database schema information, such as table names, to the low-privileged guest user.<br />
<br />
This issue affects Apache Superset: before 4.1.3.<br />
<br />
Users are recommended to upgrade to version 4.1.3, which fixes the issue.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* | 4.1.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



