Severity
High
Analysis Summary
CVE-2025-48912
An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized access to data.
Impact
- Security Bypass
Indicators of Compromise
CVE
CVE-2025-48912
Affected Vendors
Apache
Affected Products
- Apache Superset 4.1.2
Remediation
Refer to Apache Security Advisory for patch, upgrade, or suggested workaround information.

