CVE-2026-25887: Chartbrew: Remote Code Execution (RCE) via MongoDB Dataset Query
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25887?
CVE-2026-25887 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2026-25887?
To mitigate CVE-2026-25887, upgrade Chartbrew to version 4.8.1 or later.
Which versions of Chartbrew are affected by CVE-2026-25887?
CVE-2026-25887 affects Chartbrew versions prior to 4.8.1.
What is the impact of CVE-2026-25887?
The impact of CVE-2026-25887 allows attackers to execute arbitrary code on the server via MongoDB dataset queries.
Is CVE-2026-25887 applicable to cloud deployments of Chartbrew?
Yes, CVE-2026-25887 is applicable to any deployment of Chartbrew that runs a vulnerable version, including cloud deployments.