SQL Injection Vulnerability in OpenMetadata by OpenMetadata
CVE-2025-50466
7.1HIGH
What is CVE-2025-50466?
OpenMetadata versions up to 1.4.4 are susceptible to an SQL injection vulnerability that could allow attackers to manipulate database queries. This occurs in the listCount function within the TestDefinitionDAO interface, allowing exploitation through the entityType parameter. By crafting a vulnerable SQL query, attackers could potentially extract sensitive data from the underlying database.