FILTERING BY: CLEAR FILTER

Metabase SQL Injection Zero-Day Exploited for Mass Data Exfiltration

A critical zero-day SQL injection (SQLi) vulnerability in the Metabase business intelligence platform has been actively exploited to facilitate mass data exfiltration. The vulnerability arises from insufficient input sanitization within the query engine, permitting unauthenticated or low-privileged attackers to bypass security filters and execute arbitrary SQL commands against the application's backend database. This flaw enables attackers to bypass authorization controls via specific API endpoints, leading to the compromise of sensitive customer PII, administrative credentials, and potentially all connected data sources. Immediate remediation through vendor-supplied patches is required to mitigate the risk of full database takeover and secondary lateral movement into integrated data environments.

Critical RCE Chain in LangGraph via SQLi and Unsafe Deserialization

A critical vulnerability chain in the LangGraph AI framework enables unauthenticated Remote Code Execution (RCE) on self-hosted deployments. The exploit originates from a SQL Injection (SQLi) flaw within the framework’s checkpointer mechanism, specifically affecting SQLite and Redis implementations. By leveraging this SQLi, attackers can manipulate the agent's state to trigger unsafe deserialization of state objects. This allows for arbitrary command execution on the underlying host server. Organizations running self-hosted AI agent orchestration infrastructures that expose state management endpoints to untrusted networks are at immediate risk of full system compromise and unauthorized manipulation of agent logic.


LINK COPIED TO CLIPBOARD