Local Link Access Protection Circumvention in Metabase by Metabase Inc.
CVE-2025-30371
What is CVE-2025-30371?
Metabase, a popular business intelligence tool, has a vulnerability that allows circumvention of local link access protection on the GeoJson endpoint. This issue affects self-hosted instances of Metabase that utilize the GeoJson feature, especially when these instances are not isolated from other unsecured resources. It poses a risk of unauthorized access to sensitive information stored within these systems. The problem is resolved in versions v0.52.16.4, v1.52.16.4, v0.53.8, and v1.53.8. Users are encouraged to upgrade to these patched versions or consider migrating to Metabase Cloud for enhanced security. Alternatively, deploying Metabase in a dedicated subnet with strict outbound port controls can help mitigate the risks associated with this vulnerability.
Affected Version(s)
metabase < 0.52.16.4 < 0.52.16.4
metabase < 1.52.16.4 < 1.52.16.4
metabase < 0.53.8 < 0.53.8