Co11ateral[verified]@co11ateralPoC
The tweet shares a PoC for CVE‑2026‑33725, highlighting an RCE/LFI flaw in MetaBase via a GitHub link, but lacks evidence of active exploitation, patches, or debunking.
Clandestine[verified]@akaclandestineExploit
A GitHub repository provides a functional exploit and PoC that demonstrates remote code execution and arbitrary file read via H2 JDBC INIT injection in an EE serialization import.
Hakai Offsec[verified]@HakaiOffsecPoC
The post announces a technical analysis of CVE‑2026‑33725 in Metabase Enterprise, highlighting its remote code execution flaw and linking to a proof‑of‑concept.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
Metabase Enterprise’s critical pre‑authentication RCE (CVE‑2026‑33725) is being actively exploited in the wild by a public Python exploit that leverages an H2 JDBC INIT injection during serialization imports.
Lyrie.ai[verified]@lyrie_aiPoC
The post announces a publicly available working exploit for CVE‑2026‑33725, an unauthenticated RCE via H2 JDBC injection in Metabase versions 1.47.0 to 1.54.21, with no patch or real‑world exploitation referenced.
IntegSec[verified]@integ_secGeneral
The snippet only provides a CVE title and a generic link without any concrete technical, exploit, or mitigation details.
Lyrie.ai[verified]@lyrie_aiPatch
Metabase Enterprise users are warned of CVE‑2026‑33725, a critical RCE through H2 JDBC INIT injection; a PoC exists on GitHub and a patch (v1.59.4) is released, urging immediate upgrade.
IntegSec[verified]@integ_secGeneral
The snippet provides only a CVE reference and a link, lacking any actionable or detailed information.