Cube develops a data-analytics and visualization framework (Cube.js) that exposes a query interface to client applications, with observed vulnerabilities clustering around input validation, SQL injection, and error-handling defects typical of database-facing middleware. The vendor's footprint is narrow in volume but sits at the intersection of user input and backend query construction, making input-sanitization and privilege-boundary weaknesses a recurring focus for defenders integrating this component. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cube over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23510HIGH cube-js is a headless business intelligence platform. In version 0.31.23 all authenticated Cube clients could bypass SQL row-level security and run arbitrary SQL via the newly intr | Dec 9, 2022 | 8.8 | 28 | NO | NO |
CVE-2026-25958HIGH Cube is a semantic layer for building data applications. From 0.27.19 to before 1.5.13, 1.4.2, and 1.0.14, it is possible to make a specially crafted request with a valid API token | Feb 9, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-25957MEDIUM Cube is a semantic layer for building data applications. From 1.1.17 to before 1.5.13 and 1.4.2, it is possible to make the entire Cube API unavailable by submitting a specially cr | Feb 9, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-50709HIGH Cube is a semantic layer for building data applications. Prior to version 0.34.34, it is possible to make the entire Cube API unavailable by submitting a specially crafted request | Dec 13, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cube.
Media articles that mention a CVE ID that affects a product developed by Cube — matched by CVE ID, not by vendor name.