metricflow is vulnerable to Server-Side Template Injection (SSTI)
88
High Risk
MetricFlow passes caller or model controlled where_sql_template values to an unsandboxed Jinja environment in both the filter converter and the where filter spec factory. A crafted template runs arbitrary Jinja expressions and reaches Python object internals during query construction, leading to arbitrary code execution via server-side template injection. The fix runs both rendering paths through Jinja's SandboxedEnvironment and rejects templates that raise a SecurityError.
You are affected if you are using a version that falls within the vulnerable range and where_sql_template values can come from untrusted or model-generated input.
metricflow is vulnerable to Server-Side Template Injection (SSTI) in versions 0.210.0 - 0.212.0.
Upgrade the metricflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.