A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user.
This issue affects Apache Superset: before 5.0.0.
Users are recommended to upgrade to version 5.0.0, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Aug 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache superset |
|
Vendors & Products |
Apache
Apache superset |
Thu, 14 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 14 Aug 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets executed in the victim's browser when they hover over the chart, potentially leading to session hijacking or the execution of arbitrary commands on behalf of the user. This issue affects Apache Superset: before 5.0.0. Users are recommended to upgrade to version 5.0.0, which fixes the issue. | |
Title | Apache Superset: Stored XSS on charts metadata | |
Weaknesses | CWE-80 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: apache
Published: 2025-08-14T13:17:33.843Z
Updated: 2025-08-14T13:52:26.910Z
Reserved: 2025-08-13T12:38:31.381Z
Link: CVE-2025-55672

Updated: 2025-08-14T13:52:20.471Z

Status : Awaiting Analysis
Published: 2025-08-14T14:15:34.347
Modified: 2025-08-15T13:13:07.817
Link: CVE-2025-55672

No data.