Cross-site scripting in Metabase - CVE-2022-24855
Published: April 14, 2022 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote attacker to perform cross-site scripting attacks.
The vulnerability exists due to cross-site scripting in /_internal endpoint when handling requests to the internal development endpoint. A remote attacker can send a specially crafted link to perform cross-site scripting attacks.
This could be leveraged for phishing attempts that may lead to account takeover.