CVE-2026-25958 | cube-js cube up to 1.0.13/1.4.1/1.5.12 Request reliance on untrusted inputs in a security decision (GHSA-v226-32c7-x2v7)
A vulnerability has been found in cube-js cube up to 1.0.13/1.4.1/1.5.12 and classified as problematic. Impacted is an unknown function of the component Request Handler. Performing a manipulation results in reliance on untrusted inputs in a security decision.
This vulnerability is known as CVE-2026-25958. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.