Metabase zero-day exploited; urgent patches advised
🔒 Metabase disclosed a maximum-severity zero-day vulnerability (CVSS 10.0) affecting versions from x.58.0 through x.63.x that has been actively exploited in the wild. The flaw allows unauthenticated SQL injection into the application database, enabling attackers to gain administrator access, alter configurations, steal stored database credentials, and exfiltrate data. Metabase Cloud has been patched; self-hosted users must apply updates immediately or block the "/api/session/reset_password" endpoint as an interim mitigation.
