Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.2

Chartbrew: Unpatched Charts Can Let Hackers Run Code on Your Server

CVE-2026-25887
Summary

An older version of Chartbrew, a web app that creates charts from data, had a security flaw that let attackers run any code they wanted on the server. If you're using an outdated version, update to the latest version (4.8.1) to fix the issue. This will protect your data and prevent potential security risks.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
depomo chartbrew <= 4.8.1 –
Original title
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability...
Original description
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.
nvd CVSS3.1 7.2
Vulnerability type
CWE-94 Code Injection
Published: 6 Mar 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026