A vulnerability labeled as problematic has been found in Metabase up to 1.59.3. This affects an unknown function of the file /api/ee/serialization/import of the component Serialization Import Endpoint. The manipulation results in deserialization. This vulnerability is known as CVE-2026-33725. It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded.
| Vendor | Product | Versions |
|---|---|---|
| metaba | metaba | < 1.54.22, >= 1.55.0, < 1.55.22, >= 1.56.0, < 1.56.22, >= 1.57.0, < 1.57.16, >= 1.58.0, < 1.58.10, >= 1.59.0, < 1.59.4, 1.59.3 |
Updated vendor and product names, added a new description, and corrected exploit availability to false.
Updated affected versions to include 1.59.3, changed severity to CRITICAL, and noted that no exploit is available.
Initial creation