Product overview
Metabase is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Main capabilities
- Networked or application service delivery
- Administrative and operational interfaces
- Versioned maintenance and security updates
Typical use
Used to provide application, infrastructure or operational services to other systems and users.
Deployment
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page ↗.
Collected lifecycle data
| Product | Metabase |
|---|
| Release | 59 |
|---|
| End of Support | 1 September 2026 |
|---|
| Date precision | Day |
|---|
Known exploited vulnerabilities
Catalogue updated 11 Sep 2026These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Metabase SQL Injection Vulnerability
Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data.
Metabase · MetabaseRansomware use: Unknown
CISA entry ↗Metabase GeoJSON API Local File Inclusion Vulnerability
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
Metabase · MetabaseRansomware use: Unknown
CISA entry ↗
Package vulnerability advisories
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Source evidence
PRIMARYManual
Metabase official lifecycle source
Version | Released | End of life | Metabase 59 | February 12, 2026 | September 1, 2026
Publisher identity used by product-specific official-source collectors.
First collected 12 Sep 2026 · Last collected 12 Sep 2026 · Review state accepted
Open official vendor source ↗