CVE-2025-5895

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 4454ebbdc7719016bf80ca0f34859ce5cee9f6b0. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:metabase:metabase:0.54.10:*:*:*:-:*:*:*

History

10 Jul 2025, 16:26

Type Values Removed Values Added
References () https://github.com/metabase/metabase/commit/4454ebbdc7719016bf80ca0f34859ce5cee9f6b0 - () https://github.com/metabase/metabase/commit/4454ebbdc7719016bf80ca0f34859ce5cee9f6b0 - Patch
References () https://vuldb.com/?submit.585795 - () https://vuldb.com/?submit.585795 - Third Party Advisory, VDB Entry
References () https://github.com/metabase/metabase/pull/57011 - () https://github.com/metabase/metabase/pull/57011 - Exploit, Issue Tracking, Patch
References () https://github.com/metabase/metabase/pull/57011#pullrequestreview-2792664135 - () https://github.com/metabase/metabase/pull/57011#pullrequestreview-2792664135 - Exploit, Issue Tracking, Patch
References () https://vuldb.com/?ctiid.311667 - () https://vuldb.com/?ctiid.311667 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.311667 - () https://vuldb.com/?id.311667 - Third Party Advisory, VDB Entry
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:metabase:metabase:0.54.10:*:*:*:-:*:*:*
CWE CWE-1333
First Time Metabase metabase
Metabase

10 Jun 2025, 16:15

Type Values Removed Values Added
CWE CWE-1333
CWE-400
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown

09 Jun 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 20:15

Updated : 2025-07-10 16:26


NVD link : CVE-2025-5895

Mitre link : CVE-2025-5895


JSON object : View

Products Affected

metabase

  • metabase
CWE
CWE-1333

Inefficient Regular Expression Complexity