SQL injection in Metabase - #VU130153
Published: February 19, 2021 / Updated: May 5, 2026
Metabase
Metabase
Description
The vulnerability allows a remote user to inject SQL commands.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in wrapper functions for Redshift REGEXP_SUBSTR and REGEXP_REPLACE and Postgres substring() when processing user-supplied regex patterns. A remote user can supply a specially crafted regex pattern to inject SQL commands.
Only installations that use a Postgres or Amazon Redshift data warehouse are affected.