CVE-2025-55674

Severity CVSS v4.0:
MEDIUM
Type:
CWE-89 SQL Injection
Publication date:
14/08/2025
Last modified:
04/11/2025

Description

A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions that were intended to be disabled, leading to the disclosure of sensitive database information like the software version.<br /> <br /> This issue affects Apache Superset: before 5.0.0.<br /> <br /> Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:* 5.0.0 (excluding)