Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Chartbrew versions before 4.8.1: Attacker can run unauthorized code

CVE-2026-25888
Summary

Chartbrew, a web app that connects to databases and APIs, has a security flaw that could allow an attacker to execute unauthorized code on a server. This could lead to data theft or other malicious activities. Update to version 4.8.1 to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
depomo chartbrew <= 4.8.1 –
Original title
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability...
Original description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API. This issue has been patched in version 4.8.1.
nvd CVSS3.1 8.8
Vulnerability type
CWE-94 Code Injection
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026