framework just told every customer their data leaked — the bug was a password reset box

A password-reset endpoint with a CVSS 10.0 score let attackers become Metabase admins with zero credentials — and Framework's customers paid for it.

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVSS 10.0, no CVE assigned: Metabase's own advisory, GHSA-vwf4-m7j8-wcjf, calls it maximum severity.

The short version

The bug lives in the unauthenticated POST /api/session/reset_password endpoint across six version branches, 1.58 through 1.63.

The short version

Attackers accessed Framework's Metabase Cloud instance on August 3, 2026; Metabase notified Framework on August 6.

The short version

Exposed data: full names, emails, phone numbers, login IPs, billing/shipping addresses, and for business accounts, VAT and EIN numbers. Payment data was not touched.

The short version

Fix versions: 1.58.24, 1.59.21, 1.60.17, 1.61.11, 1.62.9, or 1.63.5 — self-hosted instances must upgrade manually; Cloud customers are already patched.

My honest take

This isn't really a Metabase story — it's a reminder that your vendor's vendor is your attack surface now. Framework didn't write the buggy code, and it still had to send a breach notice to every…

Aliteq

Read the full story

framework just told every customer their data leaked — the bug was a password reset box

Read the full story on Aliteq