Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Chartbrew versions before 4.8.1: Attacker can run unauthorized code
CVE-2026-25888
Summary
Chartbrew, a web app that connects to databases and APIs, has a security flaw that could allow an attacker to execute unauthorized code on a server. This could lead to data theft or other malicious activities. Update to version 4.8.1 to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| depomo | chartbrew | <= 4.8.1 | – |
Original title
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability...
Original description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via a vulnerable API. This issue has been patched in version 4.8.1.
nvd CVSS3.1
8.8
Vulnerability type
CWE-94
Code Injection
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026