PyPI: apache-superset

CVE-2025-55672

Safety vulnerability ID: SFTY-20250815-18115

Safety legacy ID: pyup.io-78711

Affected versions of the apache‑superset package are vulnerable to Cross‑site Scripting (XSS) due to improper sanitization of chart label inputs. The chart visualization module allows an authenticated user with edit‑chart permissions to inject a malicious payload into a chart’s column label, which is not properly sanitized and executes when the victim hovers over the chart. An attacker with such access can exploit this by crafting a chart label containing script code, triggering execution in other users’ browsers upon hover and potentially leading to session hijacking or arbitrary command execution on behalf of the user.

Created at: Nov 5, 2025Updated at: Nov 5, 2025

Overview

Apache Superset's chart visualization has a stored Cross-Site Scripting (XSS) vulnerability

Advisory

Affected versions of the apache‑superset package are vulnerable to Cross‑site Scripting (XSS) due to improper sanitization of chart label inputs. The chart visualization module allows an authenticated user with edit‑chart permissions to inject a malicious payload into a chart’s column label, which is not properly sanitized and executes when the victim hovers over the chart. An attacker with such access can exploit this by crafting a chart label containing script code, triggering execution in other users’ browsers upon hover and potentially leading to session hijacking or arbitrary command execution on behalf of the user.

Affected Package

Affecting apache-superset package, versions
<5.0.0

Also affects

---

How to Fix

Upgrade
apache-superset
to
5.0.0
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more