Metabase dom.js parseDataUri redos

CVE Details

Basic Information

Title Metabase dom.js parseDataUri redos
Type cve
Published 2025-06-09T20:00:19.261Z
Last Seen

Product Information

Vendor n/a
Product Metabase
Version 54.10

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A regular expression complexity vulnerability in Metabase’s parseDataUri function could allow remote attackers to cause inefficient processing, potentially leading to a denial of service.
AI Severity Medium
Vendor Metabase Inc.
Product Metabase
Affected Version 54.10

Affected Products

  • n/a Metabase 54.10

Additional Information

CVE List
CWE List CWE-1333, CWE-400
Bulletin Family

Description

A vulnerability was found in Metabase 54.10. It has been classified as problematic. This affects the function parseDataUri of the file frontend/src/metabase/lib/dom.js. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The patch is named 4454ebbdc7719016bf80ca0f34859ce5cee9f6b0. It is recommended to apply a patch to fix this issue.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.