Vulnerability record · CVE-2021-41277 · published 17 November 2021
CVE-2021-41277: Metabase custom GeoJSON map feature allows local file inclusion
Metabase · Metabase
Metabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. This lets a remote, unauthenticated attacker read local files and environment variables from the server. The flaw is fixed in maintenance releases 0.40.5 and 1.40.5 and later.
Description
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, has a high CVSS score, and is listed in CISA KEV with a very high EPSS probability, indicating active exploitation.
What it is
Metabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. This lets a remote, unauthenticated attacker read local files and environment variables from the server. The flaw is fixed in maintenance releases 0.40.5 and 1.40.5 and later.
Impact
An attacker gains read access to arbitrary local files and environment variables on the Metabase host, which can expose database credentials, API keys and other secrets. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via the GeoJSON map loading path with no authentication and no user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). The description does not state whether the vulnerable endpoint is exposed by default or only after a custom map is configured.
Exploitation
CVE-2021-41277 is listed in CISA KEV (added 2024-11-12, due 2024-12-03) and has an EPSS 30-day probability of 0.97178 (99.89th percentile), indicating active exploitation. No ransomware campaign use is recorded.
What to do
- Upgrade Metabase to 0.40.5, 1.40.5 or any later release.
- If immediate upgrade is not possible, add validation rules in the reverse proxy, load balancer or WAF to filter GeoJSON map URLs before they reach the application.
- Restrict network access to the Metabase instance so it is not reachable from untrusted networks.
- Rotate any credentials or secrets that may have been exposed through environment variables or local files.
- Monitor vendor advisories for further guidance on this issue.
Detection
- Review Metabase logs for requests to the custom GeoJSON map endpoint with external or file-based URLs.
- Inspect reverse proxy, load balancer and WAF logs for URL patterns referencing local files or environment variables.
- Search for unexpected outbound requests from the Metabase host to attacker-controlled URLs.
- Check for unauthorized changes to the custom maps configuration under admin settings.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-41277 to the Known Exploited Vulnerabilities catalog on 12 November 2024 as "Metabase GeoJSON API Local File Inclusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0 | Patch |
| https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr | MitigationThird Party Advisory |
| https://github.com/metabase/metabase/commit/042a36e49574c749f944e19cf80360fd3dc322f0 | Patch |
| https://github.com/metabase/metabase/security/advisories/GHSA-w73v-6p7p-fpfr | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-41277 | US Government Resource |
Track CVE-2021-41277 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-41277), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.