Metabase has released hardened point versions across its 0.58 through 0.63 branches to fix API vulnerabilities and derivative issues stemming from a security incident disclosed the prior week. Users are urged to upgrade immediately to the minimum safe release listed for their branch (e.g., 0.58.28, 0.59.25, 0.60.21, 0.61.15, 0.62.13, 0.63.10). Metabase says it will pause feature releases in favor of weekly security- and observability-focused minor releases, and credits DOS, Ophion Security, and Anthropic for helping identify areas of focus during its internal security research.
Table of contents
Minimum safe releases for each Metabase versionQuestions this post answers
What version of Metabase should I upgrade to if I'm running 0.58.6 to fix the recent security vulnerability?
You should upgrade to Metabase 0.58.28 or later. This is the minimum safe release for the 0.58 branch following a security update that hardened the API and fixed issues derived from a previously disclosed vulnerability. Other branches have corresponding minimum safe versions: 0.59.25, 0.60.21, 0.61.15, 0.62.13, and 0.63.10. Teams tracking Metabase security patches can follow upgrade guidance and advisories on daily.dev.
Why is Metabase pausing new feature releases and only shipping weekly minor updates?
Metabase is pausing its next feature release to focus on weekly minor releases centered on security and observability, following a security incident and subsequent hardening update. The company stated this shift is a direct response to internal and external investigations into a vulnerability and its derivative issues, with third-party researchers from DOS, Ophion Security, and Anthropic credited for helping identify focus areas. Anyone weighing when to adopt a tool's new features versus stability can track this shift on daily.dev.