📦 Openmetadata

by Open Metadata

🔍 What is Openmetadata?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-28255

CRITICAL CVSS 9.8 Mar 15, 2024

CVE-2024-28255 is an authentication bypass vulnerability in OpenMetadata's JWT filter that allows attackers to access protected endpoints without valid credentials by manipulating path parameters. Thi...

CVE-2024-28253

CRITICAL CVSS 9.4 Mar 15, 2024

This vulnerability in OpenMetadata allows remote attackers to execute arbitrary code by exploiting a Spring Expression Language (SpEL) injection flaw. Attackers can send crafted PUT requests to the po...

CVE-2026-26010

HIGH CVSS 7.6 Feb 11, 2026

OpenMetadata versions before 1.11.8 leak JSON Web Tokens (JWTs) used by the ingestion-bot service through API calls from the UI. This allows any read-only user to gain highly privileged Ingestion Bot ...

CVE-2026-22244

HIGH CVSS 7.2 Jan 8, 2026

OpenMetadata versions before 1.11.4 contain a Server-Side Template Injection vulnerability in FreeMarker email templates that allows remote code execution. Attackers with administrative privileges can...

CVE-2025-50465

HIGH CVSS 7.1 Aug 8, 2025

OpenMetadata versions up to 1.4.4 contain a SQL injection vulnerability in the TestDefinitionDAO interface. Attackers can exploit the testPlatform parameter in the listCount function to execute arbitr...

CVE-2024-55238

HIGH CVSS 7.1 Apr 17, 2025

OpenMetadata versions up to 1.4.1 contain a SQL injection vulnerability in the WorkflowDAO interface's listCount function. Attackers can exploit the workflowtype and status parameters to execute arbit...

CVE-2024-28848

HIGH CVSS 8.8 Mar 15, 2024

This vulnerability allows authenticated non-admin users in OpenMetadata to execute arbitrary system commands via SpEL expression injection. Attackers can achieve remote code execution by exploiting th...

CVE-2025-50467

MEDIUM CVSS 6.5 Aug 8, 2025

OpenMetadata versions up to 1.4.4 contain a SQL injection vulnerability in the TestDefinitionDAO interface. Attackers can exploit the supportedDataTypeParam parameter in the listCount function to extr...

CVE-2025-50468

MEDIUM CVSS 6.5 Aug 8, 2025

OpenMetadata versions up to 1.4.4 contain a SQL injection vulnerability in the DocStoreDAO interface's listCount function. Attackers can exploit this by manipulating the entityType parameter to execut...