February 2026 vulnerability: What happened?
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A security researcher discovered a vulnerability in Metabase's notification API that allowed authenticated users to craft Handlebars templates capable of extracting database credentials and sending them via outbound email. The flaw arose from two independent changes: adding user-supplied Handlebars template support and exposing
Table of contents
What happened?Who was affected?Why did it happen?What did we fix?Fixed versionsWhat are we doing to prevent this in the future?ConclusionCreditsQuestions or concerns?Sort: