NPM · AUGUST 2026 · CONFIRMED

Metabase npm Package SQL Injection: Critical Threat Details

Severity
HIGH
Affected component
metabase (npm)
Patched version
Not yet available
CVE-2026-72898GHSA-VWF4-M7J8-WCJF

The Metabase npm package has been exploited in the wild via SQL injection. Users of affected versions are at risk.

What happened

A high-severity SQL injection vulnerability in the Metabase npm package has been confirmed and exploited in the wild. The vulnerability, tracked as CVE-2026-72898, allows unauthorized SQL queries to be executed. This can lead to data breaches and unauthorized access to sensitive information. The exact version range affected has not been officially published, but all users of the Metabase npm package should assume risk and take immediate action.

The exploit was first flagged on August 10, 2026, and confirmed shortly thereafter. Multiple independent sources have verified the threat, including CISA and several cybersecurity news outlets. The attack does not involve a supply-chain compromise, but direct exploitation of the SQL injection flaw.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If metabase is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the Metabase npm package, you should assume you are at risk until you have upgraded to a fixed version. The exact version range affected has not been officially published.

What should I do right now?

Upgrade to the latest version of Metabase and review your SQL queries for any signs of unauthorized access.

Has this been exploited in the wild?

Yes, the vulnerability has been confirmed to be exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats