Metabase npm Package SQL Injection: Critical Threat Details
- Severity
- HIGH
- Affected component
- metabase (npm)
- Patched version
- Not yet available
The Metabase npm package has been exploited in the wild via SQL injection. Users of affected versions are at risk.
What happened
A high-severity SQL injection vulnerability in the Metabase npm package has been confirmed and exploited in the wild. The vulnerability, tracked as CVE-2026-72898, allows unauthorized SQL queries to be executed. This can lead to data breaches and unauthorized access to sensitive information. The exact version range affected has not been officially published, but all users of the Metabase npm package should assume risk and take immediate action.
The exploit was first flagged on August 10, 2026, and confirmed shortly thereafter. Multiple independent sources have verified the threat, including CISA and several cybersecurity news outlets. The attack does not involve a supply-chain compromise, but direct exploitation of the SQL injection flaw.
What to do about it
- Upgrade to the latest version of Metabase immediately.
- Review all SQL queries for any signs of unauthorized access or unusual activity.
- Monitor the primary sources for any updates on the vulnerability and official fixes.
- No official fix has been published yet. Continue to monitor the sources below for updates.
How 0Day would have caught this
metabase is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the Metabase npm package, you should assume you are at risk until you have upgraded to a fixed version. The exact version range affected has not been officially published.
What should I do right now?
Upgrade to the latest version of Metabase and review your SQL queries for any signs of unauthorized access.
Has this been exploited in the wild?
Yes, the vulnerability has been confirmed to be exploited in the wild.
Sources
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
- [CISA KEV] CVE-2026-72898 — Metabase Metabase
- Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
- Metabase Patches Vulnerability Exploited as Zero-Day
- Framework loses customer data in Metabase zero-day attack
- Inside the Metabase SQLi: Exploited in the Wild