Security update for the Chainguard Metabase image
Resolved
Aug 7, 2026 at 10:49am UTC
A patched Chainguard Metabase image has been released and has propagated across all affected image tags.
What was addressed. This update remediates three upstream Metabase advisories: GHSA-vwf4-m7j8-wcjf (fixed directly in the image), and GHSA-8hmm-hrhg-ppqp and GHSA-r8h2-qpfx-mx59 (mitigated by disabling public dashboard sharing by default).
Public dashboard sharing is now off by default. If you need to re-enable it, set the environment variable MBENABLEPUBLIC_SHARING to true — but only if your instance is not publicly reachable. We intend to restore the previous default once upstream releases a full fix.
Please note on vulnerability scanners. Upstream Metabase has not yet cut a versioned release, so the image version number remains within the advisories' affected range. Scanners may therefore flag the patched image as vulnerable even though the fix and mitigations are in place. We will update the version once upstream publishes a release.
Recommended actions. If you have not already done so, complete the steps from our earlier update: update to the latest patched image, revoke active sessions, delete any unrecognized API keys, audit administrator accounts, and rotate credentials for any connected databases. Upgrading alone does not remove access an attacker may have already established, so these steps remain important.
This incident is now resolved. Thank you for your patience.
Affected services
Created
Aug 7, 2026 at 10:22am UTC
We have identified of a security vulnerability in upstream Metabase that affects the Metabase container image published by Chainguard. A small number of customers running the affected image may be exposed until they update.
A patched image is currently being built and is expected to be released shortly. We will be monitoring propagation to confirm all affected image tags are updated.
Recommended actions for anyone running our Metabase image. These apply regardless of whether you have updated, because some steps address exposure that an update alone does not remove:
Update to the latest patched Chainguard Metabase image once available.
Block access to the password reset endpoint (/api/session/reset_password) at your ingress.
Revoke active sessions.
Delete any API keys you do not recognize.
Audit administrator accounts for unexpected changes.
Rotate credentials for any databases connected to Metabase.
Please note: upgrading the image alone is not sufficient, as any attacker-created API keys or previously exposed database credentials will persist after an upgrade.
We will post a further update once the patched image has released.
Affected services