Mathesar Saved Exploration Access Vulnerability Allowing Unauthorized Read, Replace, or Delete Operations

Vulnerability

A vulnerability in Mathesar versions 0.2.0 prior to 0.10.0 allows authenticated users to access, modify, or delete saved explorations in databases where they are not collaborators. The issue arises because certain RPC methods do not verify the user's collaboration status before performing actions based on the exploration ID. This vulnerability impacts the application's management of exploration definitions, including metadata and transformation details. However, it does not grant unauthorized access to database credentials or underlying PostgreSQL table data.

Impact

Exploitation of this vulnerability allows unauthorized users to read, replace, or delete saved explorations in non-collaborator databases, potentially leading to unauthorized modification or loss of exploration data.

Remediation

Users are advised to upgrade to Mathesar version 0.10.0 or later. For multi-user deployments, there is no complete workaround, but those where all users are mutually trusted are less exposed.

Added: May 15, 2026, 7:39 PM
Updated: May 15, 2026, 7:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
8.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.