CVE-2026-25887

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/03/2026
Last modified:
10/03/2026

Description

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:depomo:chartbrew:*:*:*:*:*:*:*:* 4.8.1 (excluding)