CVE-2026-92813: Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass
Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing unauthenticated attackers to reach loopback services. Attackers can save a malicious GeoJSON entry with 0.0.0.0 and trigger requests that return loopback service responses to unauthenticated callers.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker can exploit it if they can save a malicious custom GeoJSON entry and cause its URL to be requested. The resulting loopback service response can be returned to unauthenticated callers.
What internal targets are exposed?
The described bypass uses the unspecified address 0.0.0.0 to reach services bound to loopback. The available data does not identify particular loopback services or ports.
Which Metabase versions are affected?
Metabase through version 0.63.18 is affected according to the provided information.