Local Link Access Protection Circumvention in Metabase by Metabase Inc.
CVE-2025-30371
What is CVE-2025-30371?
Metabase, a popular business intelligence tool, has a vulnerability that allows circumvention of local link access protection on the GeoJson endpoint. This issue affects self-hosted instances of Metabase that utilize the GeoJson feature, especially when these instances are not isolated from other unsecured resources. It poses a risk of unauthorized access to sensitive information stored within these systems. The problem is resolved in versions v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Users are encouraged to upgrade to these patched versions or consider migrating to Metabase Cloud for enhanced security. Alternatively, deploying Metabase in a dedicated subnet with strict outbound port controls can help mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
metabase < 0.52.16.4 < 0.52.16.4
metabase < 1.52.16.4 < 1.52.16.4
metabase < 0.53.8 < 0.53.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
