Metabase Zero-Day SQLi Actively Exploited for Data Theft
A critical, unpatched SQL injection vulnerability in Metabase’s business intelligence software (CVSS 10.0) is being actively exploited in the wild. Attackers are using this zero-day to inject arbitrary SQL, gain administrative access without authentication, and steal customer data. This vulnerability has already impacted companies like Framework and Tally, leading to data theft incidents.