cbcvebase.

Nceas Metacat vulnerabilities

4 known vulnerabilities affecting nceas/metacat.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2026-48114P2CRITICALCVSS 9.8v>= 2.0.0, < 3.0.02026-06-15
CVE-2026-48114 [CRITICAL] CWE-89 CVE-2026-48114: Metacat is data repository software that helps researchers preserve, share, and discover data. Versi Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against HARVEST_SITE_SCHEDULE via string concatenation, using a quoteString() helper that perfo
nvd
CVE-2026-47754P2CRITICALCVSS 9.3fixed in 3.0.02026-08-10
CVE-2026-47754 [CRITICAL] CWE-22 CVE-2026-47754: Metacat is data repository software that helps researchers preserve, share, and discover data. Versi Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions contain an unauthenticated path traversal in the `archiveEntryName` parameter of the `action=read` endpoint that is part of the original 1.x Metacat API. `ArchiveHandler.readArchiveEntry()` concatenates the
nvd
CVE-2026-48528P3CRITICALCVSS 9.8v>= 2.0.0, < 3.4.12026-08-14
CVE-2026-48528 [CRITICAL] CWE-89 CVE-2026-48528: Metacat is data repository software that helps researchers preserve, share, and discover data. Metac Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input that can be passed through to the backend SQL database. The `nodeId` pa
nvd
CVE-2026-50022P3MEDIUMCVSS 5.8fixed in 3.4.22026-09-17
CVE-2026-50022 [MEDIUM] CWE-441 CVE-2026-50022: Metacat is data repository software that helps researchers preserve, share, and discover data. Prior Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v2/query/solr/ to its privileged Solr backend. An unauthenticated client can select the /admin/file handler, and So
nvd
Nceas Metacat vulnerabilities | cvebase