PyPI: apache-superset

CVE-2025-55673

Safety vulnerability ID: SFTY-20250819-07401

Safety legacy ID: pyup.io-78845

Affected versions of the Apache Superset package are vulnerable to Information Disclosure due to improper access control on query metadata. The `/chart/data` endpoint returns a query field in its API response payload when guest users access charts, exposing database schema information, including table names that should not be accessible to low-privileged users.

Created at: Nov 5, 2025Updated at: Nov 5, 2025

Overview

Apache Superset data query improperly discloses database schema information to low-privileged guest user

Advisory

Affected versions of the Apache Superset package are vulnerable to Information Disclosure due to improper access control on query metadata. The `/chart/data` endpoint returns a query field in its API response payload when guest users access charts, exposing database schema information, including table names that should not be accessible to low-privileged users.

Affected Package

Affecting apache-superset package, versions
<4.1.3.post1

Also affects

---

How to Fix

Upgrade
apache-superset
to
4.1.3.post1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more