CVE-2023-38646

critical

Description

Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1 allow attackers to execute arbitrary commands on the server, at the server's privilege level. Authentication is not required for exploitation. The other fixed versions are 0.45.4.1, 1.45.4.1, 0.44.7.1, 1.44.7.1, 0.43.7.2, and 1.43.7.2.

References

https://github.com/nuclide-research/metabase-cve-2023-38646

https://github.com/jonathan-corbin/htb-cve-pocs

https://github.com/jonathan-corbin/cve-arsenal

https://github.com/1392081456/sigma-detection-rules

https://github.com/BreezeGalaxy/CVE-2023-38646

https://github.com/cyberwithcyril/VulhubPenTestingReport

https://github.com/XiaomingX/cve-2023-38646-poc

https://github.com/Red4mber/CVE-2023-38646

https://github.com/AnvithLobo/CVE-2023-38646

https://github.com/nickswink/CVE-2023-38646

https://github.com/SUT0L/CVE-2023-38646

https://github.com/Boogipop/MetabaseRceTools

https://github.com/alexandre-pecorilla/CVE-2023-38646

https://github.com/joaoviictorti/CVE-2023-38646

https://github.com/thatformat/Hvv2023

https://github.com/GREENHAT7/Hvv2023

https://github.com/fidjiw/CVE-2023-38646-POC

https://github.com/raytheon0x21/CVE-2023-38646

https://github.com/lazysec0x21/CVE-2023-38646

https://github.com/LazyySec/CVE-2023-38646

https://github.com/hheeyywweellccoommee/CVE-2023-38646-glwax

https://github.com/Chocapikk/CVE-2023-38646

https://github.com/0xrobiul/CVE-2023-38646

https://github.com/Loginsoft-Research/Linux-Exploit-Detection

https://www.metabase.com/blog/security-advisory

https://news.ycombinator.com/item?id=36812256

https://github.com/metabase/metabase/releases/tag/v0.46.6.1

https://github.com/metabase/metabase/issues/32552

https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-42445

http://packetstormsecurity.com/files/177138/Metabase-0.46.6-Remote-Code-Execution.html

http://packetstormsecurity.com/files/174091/Metabase-Remote-Code-Execution.html

Details

Source: Mitre, NVD

Published: 2023-07-21

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.98677