Framework discloses data breach via Metabase zero-day vulnerability
Attackers exploited a critical flaw in the Metabase API to access customer contact and delivery data.
Talivio News · Global1 min read
Aa
T
Laptop manufacturer Framework has suffered a data breach following the exploitation of a zero-day vulnerability in Metabase.
The breach involved the loss of contact and delivery data belonging to both private and commercial customers. Framework stated that payment and order information were not compromised during the incident.
Metabase identified an attack on its cloud instances on August 3rd using a previously unknown zero-day vulnerability. The vulnerability is located in the API endpoint used for resetting user passwords.
10.0 CVSS Score
The Metabase vulnerability is classified as critical.
The vulnerability affects all Metabase versions from 58 to 63, spanning both cloud-based and self-hosted solutions. Following the discovery, Metabase released security advisories and updates.
Metabase stated that cloud customers are already secure, though the company did not specify the number of customers who had experienced data leaks. Framework has informed the relevant supervisory authorities about the attack and hired an IT forensics company to investigate the breach. Additionally, Framework changed the access credentials to its Metabase cloud database.
Updates
Framework disclosed that customer data accessed included names, login IPs, addresses, phone numbers, and emails — expanding the previously reported scope beyond just contact and delivery data — and confirmed it notified customers via email on August 6, while also stating no unauthorized access occurred outside Metabase; Metabase, meanwhile, is collaborating with a third-party forensic firm to investigate the breach, which can be detected in logs via a POST to /api/session/reset_password followed by a call to /api/user/current, and has advised affected users to block that endpoint as a temporary safeguard.
Framework confirmed it notified customers via email on August 6, clarified that no systems beyond Metabase were compromised, and is revising its third-party data storage practices; Metabase, meanwhile, is collaborating with a forensic firm to assess the breach, has flagged the /api/session/reset_password endpoint as the attack vector, and issued preliminary guidance urging users to block it until patching is possible.
Framework confirmed the breach exposed customer names, login IPs, addresses, phone numbers, and emails, with additional sensitive data—including company name, VAT, EIN, and billing email—compromised for Business customers; Metabase, which disclosed the vulnerability as an unauthenticated SQL injection flaw exploitable via /api/session/reset_password, has patched all affected versions (0.58.24 through 0.63.5) and recommended immediate session revocation and credential rotation, while third parties like Tally and LexisNexis also reported impacts, with Tally confirming stolen password hashes but no form data, and LexisNexis temporarily disconnecting affected systems.