Lightdash

Lightdash

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 20.08.2026 22:18:05
  • Zuletzt bearbeitet 21.08.2026 16:18:16

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat/GoogleChatClient.ts and in packages/backend/src/clients/MicrosoftTeams/MicrosoftTeamsClient.ts. In a...

  • EPSS 0.58%
  • Veröffentlicht 30.08.2024 23:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject malicious scripts into vulnerable web pages. ...

  • EPSS 1.93%
  • Veröffentlicht 30.08.2024 23:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements which point to a threat actor controlled source can trigger an SSRF reque...

Exploit
  • EPSS 6.34%
  • Veröffentlicht 19.06.2023 02:15:08
  • Zuletzt bearbeitet 12.12.2024 01:24:19

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.