Metabase Just Got a Perfect 10/10, And Not in a Good Way
A CVSS 10.0 SQL injection zero-day hit Metabase’s password reset endpoint, giving attackers admin access without authentication. Framework, Tally, and LexisNexis are confirmed victims. Here’s what to do.