GHSA-pqqf-7hxm-rj5r

Suggest an improvement
Source
https://github.com/advisories/GHSA-pqqf-7hxm-rj5r
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-pqqf-7hxm-rj5r/GHSA-pqqf-7hxm-rj5r.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pqqf-7hxm-rj5r
Aliases
Published
2026-02-11T14:23:02Z
Modified
2026-02-18T23:43:46Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
Summary
Leaky JWTs in OpenMetadata exposing highly-privileged bot users
Details

Summary

Calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres)

Details

Any read-only user can gain access to a highly privileged account, typically which has the Ingestion Bot Role. This enables destructive changes in OpenMetadata instances, and potential data leakage (e.g. sample data, or service metadata which would be unavailable per roles/policies).

PoC

I was able to extract the JWT used by the bot/agent populating sample_athena.default in the Collate Sandbox. To prove this out, I mutated the description to this UUID: fe2e4cc1-da72-4acf-8535-112a3cfa9c7e, which you can see @ https://sandbox.open-metadata.org/database/sample_athena.default.

Steps to Reproduce

  • Create a Collate Sandbox account; these are non-admin accounts by default with minimal permissions.

  • Open the Developer Console

  • Go to the Services Page. In this case, sample_athena, though other services

  • In the Network tab, introspect the request made to api/v1/services/ingestionPipelines, and find the jwtToken in the response: image

  • Use the JWT to issue (potentially destructive) API calls image

  • Resulting mutated description: image

Note that this is also the case for these services, among others:

Proposed Remediation

Redact jwtToken in API payload. Implement role-based filtering - Only return JWT tokens to users with explicit admin/service account permissions (for Admins) Rotate Ingestion Bot Tokens in affected environments

Impact

What kind of vulnerability is it? Who is impacted?

  • Vulnerability Type: Privilege Escalation
  • Risk: User impersonation, even for those with read-only access, can lead to destructive outcomes if malicious actors leverage the leaked JWT.
Database specific
{
    "cwe_ids":  [
        "CWE-269"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-11T14:23:02Z",
    "nvd_published_at":  "2026-02-11T21:16:21Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.open-metadata:openmetadata-sdk

Package

Name
org.open-metadata:openmetadata-sdk
View open source insights on deps.dev
Purl
pkg:maven/org.open-metadata/openmetadata-sdk

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.11.8

Affected versions

1.*
1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.10.8
1.10.9
1.10.10
1.10.11
1.10.12
1.10.13
1.10.14
1.11.0-rc1
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-pqqf-7hxm-rj5r/GHSA-pqqf-7hxm-rj5r.json"