PT-2025-23275 · Apache · Apache Superset

·

CVE-2025-48912

·

Published

2025-05-30

·

Updated

2026-07-07

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache Superset versions prior to 4.1.2
Description An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into sqlExpression fields. This allowed the execution of sub-queries to evade parsing defenses, ultimately granting unauthorized access to data.
Recommendations For Apache Superset versions prior to 4.1.2, update to version 4.1.2 to resolve the issue. As a temporary workaround, consider restricting access to the sqlExpression fields to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06616
BIT-SUPERSET-2025-48912
CVE-2025-48912
GHSA-8W7F-8PR9-XGWJ
PYSEC-2026-1164

Affected Products

Apache Superset