Severity: 

Affected versions:

- Apache Superset before 5.0.0

Description:

A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's 
chart visualization. An authenticated user with permissions to edit charts can 
inject a malicious payload into a column's label. The payload is not properly 
sanitized and gets executed in the victim's browser when they hover over the 
chart, potentially leading to session hijacking or the execution of arbitrary 
commands on behalf of the user.

This issue affects Apache Superset: before 5.0.0.

Users are recommended to upgrade to version 5.0.0, which fixes the issue.

Credit:

Pedro Sousa (coordinator)
Jobar (finder)
Mehmet Yavuz (remediation developer)

References:

https://www.cve.org/CVERecord?id=CVE-2025-55672

Reply via email to