← Vulnerability feed

Vulnerability record · CVE-2021-41277 · published 17 November 2021

CVE-2021-41277: Metabase custom GeoJSON map feature allows local file inclusion

Metabase · Metabase

Metabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. This lets a remote, unauthenticated attacker read local files and environment variables from the server. The flaw is fixed in maintenance releases 0.40.5 and 1.40.5 and later.

7.5 CVSS 3.1 High CISA KEV since 12 Nov 2024 EPSS 97% · top 0.1% CWE-200 · Information exposureCWE-22 · Path traversal
7.5CVSS 3.1 base score, v2 5.0
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the application.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is remotely exploitable without authentication, has a high CVSS score, and is listed in CISA KEV with a very high EPSS probability, indicating active exploitation.

What it is

Metabase does not validate URLs supplied through the custom GeoJSON map setting (admin->settings->maps->custom maps->add a map) before loading them. This lets a remote, unauthenticated attacker read local files and environment variables from the server. The flaw is fixed in maintenance releases 0.40.5 and 1.40.5 and later.

Impact

An attacker gains read access to arbitrary local files and environment variables on the Metabase host, which can expose database credentials, API keys and other secrets. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network via the GeoJSON map loading path with no authentication and no user interaction required (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). The description does not state whether the vulnerable endpoint is exposed by default or only after a custom map is configured.

Exploitation

CVE-2021-41277 is listed in CISA KEV (added 2024-11-12, due 2024-12-03) and has an EPSS 30-day probability of 0.97178 (99.89th percentile), indicating active exploitation. No ransomware campaign use is recorded.

What to do

  • Upgrade Metabase to 0.40.5, 1.40.5 or any later release.
  • If immediate upgrade is not possible, add validation rules in the reverse proxy, load balancer or WAF to filter GeoJSON map URLs before they reach the application.
  • Restrict network access to the Metabase instance so it is not reachable from untrusted networks.
  • Rotate any credentials or secrets that may have been exposed through environment variables or local files.
  • Monitor vendor advisories for further guidance on this issue.

Detection

  • Review Metabase logs for requests to the custom GeoJSON map endpoint with external or file-based URLs.
  • Inspect reverse proxy, load balancer and WAF logs for URL patterns referencing local files or environment variables.
  • Search for unexpected outbound requests from the Metabase host to attacker-controlled URLs.
  • Check for unauthorized changes to the custom maps configuration under admin settings.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-41277 to the Known Exploited Vulnerabilities catalog on 12 November 2024 as "Metabase GeoJSON API Local File Inclusion Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 December 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-72898Metabase unauthenticated SQL injection in reset_password endpointMetabase exposes a database endpoint, '/reset_password', that fails to neutralize attacker-supplied SQL, allowing arbitrary SQL injection. Because th…KEVEPSS 19%analysed9.8CVE-2023-37470Metabase code injection vulnerabilityMetabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3…EPSS 1.3%9.8CVE-2023-38646Metabase unauthenticated remote command executionMetabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server at the serve…EPSS 99%analysed9.6CVE-2023-32680Metabase missing authentication for critical function vulnerabilityMetabase is an open source business analytics engine. To edit SQL Snippets, Metabase should have required people to be in at least one group with nat…EPSS 0.60%9.1CVE-2026-50148Metabase vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10,…EPSS 0.77%9.1CVE-2026-59826Metabase code injection vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase di…EPSS 1.0%8.8CVE-2026-59827Metabase deserialization of untrusted data vulnerabilityMetabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances w…EPSS 3.8%8.8CVE-2022-39362Metabase vulnerabilityMetabase is data visualization software. Prior to versions 0.44.5, 1.44.5, 0.43.7, 1.43.7, 0.42.6, 1.42.6, 0.41.9, and 1.41.9, unsaved SQL queries ar…EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2021-41277), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.