PT-2026-23636 · Chartbrew · Chartbrew

Ytlamal

·

Published

2026-03-06

·

Updated

2026-03-14

·

CVE-2026-25887

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Chartbrew versions prior to 4.8.1
Description Chartbrew is a web application that connects to databases and APIs to create charts. Versions of the software prior to 4.8.1 contain a remote code execution issue stemming from the MongoDB dataset Query functionality. The issue was addressed with the release of version 4.8.1.
Recommendations Update to version 4.8.1 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25887
GHSA-X4R6-PRMW-7WVW

Affected Products

Chartbrew